Insecure Process Execution in PaperCut Print Deploy Client for Windows
CVE-2026-6645
7.3HIGH
What is CVE-2026-6645?
A vulnerability exists in the pc-printer-updater.exe component of the PaperCut Print Deploy Client for Windows that allows local attackers to exploit an insecure process execution flaw. The client, which generally operates with elevated system privileges, performs an internal validation check by calling a secondary utility without specifying an absolute file path. This omission can be exploited by an attacker who has the ability to modify the system's search path. By placing a malicious binary in the expected search order, the attacker can execute their code with SYSTEM privileges, leading to a full compromise of the affected host.
Affected Version(s)
Print Deploy Windows 0 < 1.10.4178
References
CVSS V4
Score:
7.3
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
Unknown
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Alex F. <support.solutions@jet-services.com> // JET Services
