CVE-2024-48394 Details
Description
A Time-of-Check to Time-of-Use (TOCTOU) vulnerability has been identified in the driver of the NDD Print solution, which could allow an unprivileged user to exploit this flaw and gain SYSTEM-level access on the device. The vulnerability affects version 5.24.3 and before of the software.
A Time-of-Check to Time-of-Use (TOCTOU) vulnerability has been identified in the NDD Print solution driver, affecting versions through 5.24.3. This vulnerability could allow an unprivileged user to exploit the flaw and gain SYSTEM-level access on the device. The issue arises when a Dynamic Link Library (DLL) is validated and authorized by the Windows operating system, creating a window of opportunity for exploitation before the DLL is actually used. To successfully exploit this vulnerability, an attacker would need to have already compromised the corporate network, bypassing security measures such as firewalls, intrusion detection systems, and antivirus solutions.
Users are advised to update the NDD Print Agent to version 5.24.6 or later. For those using NDD Print Host, it is recommended to update to the latest version available on the NDD portal. Specific instructions for different scenarios are provided in the NDD security bulletin.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Feb 5, 2025CISA-ADP
Assessed Feb 6, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://helpcenter-nddprint.ndd.tech/pt/seguranca-e-compliance/Current/dezembro-2024#0 | [email protected] | AdvisoryRemedyVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-367 | Time-of-check Time-of-use (TOCTOU) Race Condition | CISA-ADP |
Affected Products
| Product | Versions |
|---|---|
| NDD Print Agent | All versions |
CPE
Remediation
| |
Change History
6 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Mar 19, 2025 | CVE Modified | CISA-ADP |
| Feb 18, 2025 | CVE Modified | CISA-ADP |
| Feb 6, 2025 | CVE Modified | CISA-ADP |
| Feb 5, 2025 | New CVE Received | [email protected] |
Volerion