CVE-2018-16156 | Fujitsu PaperStream IP 1.42.0.5685 FJTWSVIC Service UninOldIS.dll ChangeUninstallString PATH untrusted search path (ID 160832 / EDB-49382)
A vulnerability classified as critical was found in Fujitsu PaperStream IP 1.42.0.5685. This affects the function ChangeUninstallString in the library UninOldIS.dll of the component FJTWSVIC Service. Such manipulation of the argument PATH as part of Named Pipe leads to untrusted search path.
This vulnerability is referenced as CVE-2018-16156. The attack can only be performed from a local environment. Furthermore, an exploit is available.