CVE-2022-25090
🟠 Łataj w tym tygodniu
Nieprawidłowe uprawnienia pliku temp.ini w Printix umożliwiają eskalację uprawnień.
CVSS
8.1
EPSS
11.0%
Exploit
poc
Vendor
kofax
Opis źródłowy (NVD)
Printix Secure Cloud Print Management through 1.3.1106.0 creates a temporary temp.ini file in a directory with insecure permissions, leading to privilege escalation because of a race condition.
exploit privilege-escalation
Brak patcha
Źródła i daty
| Źródło | Wartość |
|---|---|
| NVD – CVSS | 8.1 |
| CISA KEV (aktywnie wykorzystywane) | Nie |
| FIRST EPSS (prawdopodobieństwo exploita) | 11.0% |
| Opublikowano (NVD) | 2022-03-10 17:47:00 UTC |
| Ostatnia modyfikacja (NVD) | 2026-07-09 01:17:19 UTC |
Referencje
- http://packetstormsecurity.com/files/166242/Printix-Client-1.3.1106.0-Privilege-Escalation.html (cve@mitre.org) [Exploit, Third Party Advisory, VDB Entry]
- http://packetstormsecurity.com/files/167012/Printix-1.3.1106.0-Privilege-Escalation.html (cve@mitre.org) [Third Party Advisory, VDB Entry]
- https://github.com/ComparedArray/printix-CVE-2022-25090 (cve@mitre.org) [Third Party Advisory]
- https://www.exploit-db.com/exploits/50812 (cve@mitre.org) [Exploit, Third Party Advisory, VDB Entry]