SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2019-19363

An issue was discovered in Ricoh (including Savin and Lanier) Windows printer drivers prior to 2020 that allows attackers local privilege escalation.

HIGH 7.8EPSS 4.44%

Does this matter?

High impact if exploited, but EPSS currently rates exploitation as unlikely (4.44%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.

Description

An issue was discovered in Ricoh (including Savin and Lanier) Windows printer drivers prior to 2020 that allows attackers local privilege escalation. Affected drivers and versions are: PCL6 Driver for Universal Print - Version 4.0 or later PS Driver for Universal Print - Version 4.0 or later PC FAX Generic Driver - All versions Generic PCL5 Driver - All versions RPCS Driver - All versions PostScript3 Driver - All versions PCL6 (PCL XL) Driver - All versions RPCS Raster Driver - All version

CVSS 3.1
7.8 HIGHCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
EPSS
4.44% probability · 91th percentile
CISA KEV
Not listed
Weakness
CWE-732
Affected
ricoh/generic pcl5 driver · ricoh/pc fax generic driver · ricoh/pcl6 \(pcl xl\) driver · ricoh/pcl6 driver for universal print · ricoh/postscript3 driver · ricoh/ps driver for universal print · ricoh/rpcs driver · ricoh/rpcs raster driver
Source
cve@mitre.org

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.