Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-4qvc-25ff-jcmq

Опубликовано: 27 мар. 2024
Источник: github
Github: Не прошло ревью
CVSS3: 6.3

Описание

A user with administrative privileges can create a compromised dll file of the same name as the original dll within the HP printer’s Firmware Update Utility (FUU) bundle and place it in the Microsoft Windows default downloads directory which can lead to potential arbitrary code execution.

A user with administrative privileges can create a compromised dll file of the same name as the original dll within the HP printer’s Firmware Update Utility (FUU) bundle and place it in the Microsoft Windows default downloads directory which can lead to potential arbitrary code execution.

EPSS

Процентиль: 18%
0.00058
Низкий

6.3 Medium

CVSS3

Дефекты

CWE-94

Связанные уязвимости

CVSS3: 6.3
nvd
почти 2 года назад

A user with administrative privileges can create a compromised dll file of the same name as the original dll within the HP printer’s Firmware Update Utility (FUU) bundle and place it in the Microsoft Windows default downloads directory which can lead to potential arbitrary code execution.

CVSS3: 7.3
fstec
почти 2 года назад

Уязвимость утилиты обновления микропрограммного обеспечения принтеров HP DeskJet, позволяющая нарушителю выполнить произвольный код

EPSS

Процентиль: 18%
0.00058
Низкий

6.3 Medium

CVSS3

Дефекты

CWE-94