CVE-2023-32232
Summary
| CVE | CVE-2023-32232 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2023-07-25 01:15:00 UTC |
| Updated | 2023-08-02 19:12:00 UTC |
| Description | An issue was discovered in Vasion PrinterLogic Client for Windows before 25.0.0.836. During client installation and repair, a PrinterLogic binary is called by the installer to configure the device. This window is not hidden, and is running with elevated privileges. A standard user can break out of this window, obtaining a full SYSTEM command prompt window. This results in complete compromise via arbitrary SYSTEM code execution (elevation of privileges). |
Risk And Classification
Problem Types: NVD-CWE-noinfo
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Vasion | Printerlogic Client | All | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Client Release Notes | MISC | docs.printercloud.com | |
| Security Bulletins, OVEs, & CVEs | MISC | docs.printercloud.com | |
| PrinterLogic Rebrands As Vasion, Affirms Commitment to Expanding and Transforming its Cloud Offerings | MISC | www.vasion.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.