Vulnerability Description
An issue was discovered in Ricoh (including Savin and Lanier) Windows printer drivers prior to 2020 that allows attackers local privilege escalation. Affected drivers and versions are: PCL6 Driver for Universal Print - Version 4.0 or later PS Driver for Universal Print - Version 4.0 or later PC FAX Generic Driver - All versions Generic PCL5 Driver - All versions RPCS Driver - All versions PostScript3 Driver - All versions PCL6 (PCL XL) Driver - All versions RPCS Raster Driver - All version
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Ricoh | Generic Pcl5 Driver | - |
| Ricoh | Pc Fax Generic Driver | - |
| Ricoh | Pcl6 \(Pcl Xl\) Driver | - |
| Ricoh | Pcl6 Driver For Universal Print | >= 4.0, < 4.26 |
| Ricoh | Postscript3 Driver | - |
| Ricoh | Ps Driver For Universal Print | >= 4.0, < 4.26 |
| Ricoh | Rpcs Driver | - |
| Ricoh | Rpcs Raster Driver | - |
Related Weaknesses (CWE)
References
- http://jvn.jp/en/jp/JVN15697526/index.htmlThird Party AdvisoryVDB Entry
- http://packetstormsecurity.com/files/156082/Ricoh-Printer-Driver-Local-PrivilegeThird Party AdvisoryVDB Entry
- http://packetstormsecurity.com/files/156251/Ricoh-Driver-Privilege-Escalation.htExploitThird Party AdvisoryVDB Entry
- http://seclists.org/fulldisclosure/2020/Jan/34Mailing ListThird Party Advisory
- https://www.ricoh.com/info/2020/0122_1/Vendor Advisory
- http://jvn.jp/en/jp/JVN15697526/index.htmlThird Party AdvisoryVDB Entry
- http://packetstormsecurity.com/files/156082/Ricoh-Printer-Driver-Local-PrivilegeThird Party AdvisoryVDB Entry
- http://packetstormsecurity.com/files/156251/Ricoh-Driver-Privilege-Escalation.htExploitThird Party AdvisoryVDB Entry
- http://seclists.org/fulldisclosure/2020/Jan/34Mailing ListThird Party Advisory
- https://www.ricoh.com/info/2020/0122_1/Vendor Advisory
FAQ
What is CVE-2019-19363?
CVE-2019-19363 is a vulnerability with a CVSS score of 7.8 (HIGH). An issue was discovered in Ricoh (including Savin and Lanier) Windows printer drivers prior to 2020 that allows attackers local privilege escalation. Affected drivers and versions are: PCL6 Driver for...
How severe is CVE-2019-19363?
CVE-2019-19363 has been rated HIGH with a CVSS base score of 7.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2019-19363?
Check the references section above for vendor advisories and patch information. Affected products include: Ricoh Generic Pcl5 Driver, Ricoh Pc Fax Generic Driver, Ricoh Pcl6 \(Pcl Xl\) Driver, Ricoh Pcl6 Driver For Universal Print, Ricoh Postscript3 Driver.