Junglewise Threat Intelligence

CVE-2026-50100: Ricoh and Konica Minolta printer drivers privilege escalation

CVE-2026-50100 · Severity: high · CVSS 7.8 · Published 2026-06-15

Executive brief

Multiple printer and fax drivers from Ricoh and Konica Minolta contain a security flaw that allows a user with low-level access to a computer to gain full administrative control. This vulnerability affects software used to manage printing and faxing tasks on corporate workstations. If exploited, an attacker who has already gained basic access to a system could take over the machine, potentially leading to data theft or the installation of persistent malware.

Technical details

A privilege escalation vulnerability exists in multiple printer and LAN-FAX drivers from Ricoh and Konica Minolta (specifically the 1422W series) due to an uncontrolled search path (CWE-427). The flaw allows a local attacker with standard user privileges to place a malicious DLL in a location searched by the driver, leading to arbitrary code execution with SYSTEM or administrative privileges. The attack requires local login access but no user interaction. Vendors have released updated drivers to address the issue; users are advised to update to the latest versions (e.g., RPCS Driver > 1.5.0.0 for Konica Minolta 1422W).

Affected products

  • KONICA MINOLTA JAPAN, INC. 1422W RPCS Driver 1.5.0.0 and earlier
  • KONICA MINOLTA JAPAN, INC. 1422W PS Driver 1.3.0.0 and earlier
  • KONICA MINOLTA JAPAN, INC. 1422W PC FAX Driver 13.0 and earlier
  • Ricoh Company, Ltd. Multiple Printer and LAN-FAX Drivers

Timeline

  • 2026-06-15: disclosed
  • 2026-06-15: advisory
  • 2026-06-15: patched

References