vendor:
PaperStream IP (TWAIN)
by:
1F98D
7.8
CVSS
HIGH
Local Privilege Escalation
CWE
Product Name: PaperStream IP (TWAIN)
Affected Version From: 1.42.0.5685
Affected Version To: 1.42.0.5685
Patch Exists: YES
Related CWE: CVE-2018-16156
CPE:
Platforms Tested: Windows 10 x64
2020
PaperStream IP (TWAIN) 1.42.0.5685 – Local Privilege Escalation
A DLL hijack vulnerability exists in the FJTWSVIC service running as part of the Fujitsu PaperStream IP (TWAIN) software package. This exploit searches for a writable location, copies the specified DLL to that location and then triggers the DLL load by sending a message to FJTWSVIC over the FjtwMkic_Fjicube_32 named pipe.
Mitigation:
Update to a patched version of the software