Logan Latvala (ComparedArray)

ComparedArray

Geek Repo

Company:Bunoyo LLC

Home Page:https://bunoyo.com

Github PK Tool:Github PK Tool

Logan Latvala's repositories

printix-CVE-2022-25090

A "Creation of Temporary Files in Directory with Insecure Permissions" vulnerability in PrintixService.exe, in Printix's "Printix Secure Cloud Print Management", Version 1.3.1106.0 and below allows any logged in user to elevate any executable or file to the SYSTEM context. This is achieved by exploiting race conditions in the Installer.

Language:C#License:MITStargazers:6Issues:2Issues:0

printix-CVE-2022-29554

A "Mishandling of Input to API" or "Exposed Dangerous Method or Function" vulnerability in PrintixService.exe, in Kofax Printix's "Printix Secure Cloud Print Management", Version 1.3.1156.0 and below allows a Local Or Remote attacker the ability to attack any enterprise installation running in KioskMode by exploiting the local PrintixProxy class to invoke an error with localhost/e/?error=INVALID_CREDENTIAL&errorMessage={kioskModeValue}. When an attacker combines this with CVE-2022-29552, the attacker may change the ProgramDir registry value to invoke any program named unis000.exe.

Language:C#License:MITStargazers:3Issues:3Issues:0

printix-CVE-2022-25089

An "Incorrect Use of a Privileged API" vulnerability in PrintixService.exe, in Printix's "Printix Secure Cloud Print Management", Version 1.3.1106.0 and below allows a Local Or Remote attacker the ability change all HKEY Windows Registry values as SYSTEM context via the UITasks.PersistentRegistryData parameter.

Language:C#License:MITStargazers:2Issues:1Issues:2

printix-CVE-2022-29551

A "Exposed Dangerous Method or Function" vulnerability in PrintixService.exe, in Kofax Printix's "Printix Secure Cloud Print Management", Version 1.3.1156.0 and below allows a Local Or Remote attacker the ability to install malicious printer drivers and run them through the Printix Service. An attacker can use this to execute malicious driver code remotely to escalate their privileges to system.

Language:C#License:MITStargazers:1Issues:3Issues:0

printix-CVE-2022-29552

A "Incorrect Use of Privileged APIs" vulnerability in PrintixService.exe, in Kofax Printix's "Printix Secure Cloud Print Management", Version 1.3.1156.0 and below allows a Local Or Remote attacker the ability change any values within the LocalMachine\Software\Printix\ Registry. This was an insufficient fix to CVE-2022-25089.

Language:C#License:MITStargazers:1Issues:3Issues:0

ComparedArray

Repo for Profile Details

Stargazers:0Issues:1Issues:0

printix-CVE-2022-29553

A "Exposed Dangerous Method or Function" or "Use of Hard-coded, Security-relevant Constants" vulnerability in PrintixService.exe, in Kofax Printix's "Printix Secure Cloud Print Management", Version 1.3.1156.0 and below allows a Local Or Remote attacker the ability to override the "ProgramDir" registry value and point it to a directory that contains a malicious PrintixServiceTask.xml file. This allows an attacker the ability to escalate their privileges to a system session.

Language:C#License:MITStargazers:0Issues:3Issues:0

printix-CVE-2022-30006

[Reserved for CVE-2022-30006]

Language:C#License:MITStargazers:0Issues:2Issues:0