CVE-2026-24466
Severity CVSS v4.0:
HIGH
Type:
CWE-428
Unquoted Search Path or Element
Publication date:
09/02/2026
Last modified:
09/02/2026
Description
Products provided by Oki Electric Industry Co., Ltd. and its OEM products (Ricoh Co., Ltd., Murata Machinery, Ltd.) register Windows services with unquoted file paths. A user with the write permission on the root directory of the system drive may execute arbitrary code with SYSTEM privilege.
Impact
Base Score 4.0
8.40
Severity 4.0
HIGH
Base Score 3.x
6.70
Severity 3.x
MEDIUM
References to Advisories, Solutions, and Tools
- https://jp.ricoh.com/security/products/vulnerabilities/vul?id=ricoh-2026-000002
- https://jvn.jp/en/jp/JVN55395471/
- https://www.muratec.jp/ce/support/announce_sp_20260209.html
- https://www.oki.com/jp/printing/support/important-information/2026/info-260209/index.html
- https://www.oki.com/jp/product_security/sa_2026_0001_en.html



