A Reliance on Untrusted Inputs in a Security Decision vulnerability has been identified in the Lexmark Print Management Client.
The vulnerability results from the Lexmark Print Management Client making critical security decisions based on input data that can be controlled or modified by an unauthorized local user. The attack vector is local (AV:L), requires no privileges (PR:N) and no user interaction (UI:N), and the scope of the vulnerability extends beyond the vulnerable component (S:C), indicating the possibility of impact on other system resources.
An attacker can gain unauthorized access to sensitive data, perform unauthorized modifications, and cause system unavailability. The scope of impacts includes complete violation of confidentiality, integrity, and availability (C:H/I:H/A:H).
Apply patches available from the manufacturer in accordance with references published by Lexmark at: https://www.lexmark.com/en_us/solutions/security/lexmark-security-advisories.html
Lexmark Print Management Client — specific versions indicated in the manufacturer's references
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H