The Lexmark Printer Software G2, G3 and G4 Installation Packages have a local escalation of privilege vulnerability due to a registry entry that has an unquoted service path.
The product uses a search path that contains an unquoted element, in which the element contains whitespace or other separators. This can cause the product to access resources in a parent path.
Link | Tags |
---|---|
http://support.lexmark.com/alerts/ | vendor advisory |
http://support.lexmark.com/index?id=TE952&page=content&locale=en&userlocale=EN_US | vendor advisory |