Ricoh New Zealand Security Advisory: Privilege Escalation Vulnerability in Printer and LAN-FAX Drivers
Executive summary
This is a high-severity local privilege escalation vulnerability in Ricoh and Konica Minolta printer drivers. If an attacker can log into a device that has one of the vulnerable drivers installed, they may be able to gain full SYSTEM-level access and completely compromise the machine. Updating the affected printer drivers as soon as possible is recommended.
What is CVE-2026-50100?
A security flaw in some Ricoh and Konica Minolta printer drivers allows a user with access to a Windows computer to gain administrator/System-level privileges.
What could happen?
An attacker who can already log into a computer could:
- Trick the printer driver into loading a malicious file.
- Bypass the driver security checks.
- Run code with SYSTEM privileges (the highest level of access in Windows).
Potentially:
- Install malware
- Modify system files
- Create persistent backdoors
- Take control of the affected machine
Who is affected?
Any computer using the vulnerable Ricoh printer drivers.
How serious is it?
- CVSS Score: 8.5/10 (High)
- Requires login access: Yes
- Can be exploited remotely: Not directly, based on the information provided.
- Impact: High, because it can turn a normal user into a full administrator.
Simple risk assessment
| Question | Answer |
|---|---|
| Does an attacker need access to the PC first? | Yes |
| Can it give admin privileges? | Yes |
| Can it lead to full machine compromise? | Yes |
| Is it actively exploited? | Not indicated |
| Should affected drivers be patched? | Absolutely |
| Should the old affected drivers be removed? | Yes |
Find out more
To find out more, please visit our global security page here.
Security Information List by Vulnerability | Global | Ricoh