CVE-2022-25090 describes a privilege escalation vulnerability in Printix Secure Cloud Print Management through version 1.3.1106.0. This flaw arises from a race condition involving a temporary temp.ini file created with insecure permissions. The vulnerability carries a high CVSS score of 8.1, indicating a severe impact (confidentiality, integrity, availability) with high attack complexity, but it can be exploited remotely without user interaction. Its EPSS score suggests a low probability of exploitation in the wild. While not listed on the CISA KEV catalog and lacking widespread community discussion or media coverage, an exploit for this vulnerability is publicly available on ExploitDB. There is no evidence of active exploitation.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 1.3.1106.0CPE matchmatch criteria | cpe:2.3:a:kofax:printix:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.