Security Vulnerability in Our printer driver

A security vulnerability has been identified in the printer driver "KX Driver" developed for the functions of multifunction devices and printers provided by KYOCERA Document Solutions.
The following is an overview of the issue and how to resolve it. As of the date of publication of this notice, we have not confirmed any attacks that take advantage of this vulnerability.


【Vulnerability description】

The vulnerability relates to a vulnerability known as Microsoft Windows Unquoted Service Path Enumeration. The creation of an unquoted service may allow an attacker to run arbitrary programs (such as malware) with Windows system privileges.

Vulnerability number: CVE-2023-38634



【Countermeasures】

As a countermeasure, we provide a new "KX Driver" that addresses security vulnerability. Please install the latest driver.

*This has been addressed in the "KX Driver" (version 8.4.1716).



【Contact Information】

For more information, please contact your local distributor where you purchased the product.

KYOCERA Document Solutions Singapore Pte. Ltd.
Address: 7 Harrison Road #06-01, Singapore 369650, Singapore
Telephone (Main): +65 6741 8733
Service Hotline: +65 6747 6042
Fax: +65 6748 3788
(Monday to Friday; 09:00 – 17:00)