---
id: CVE-2018-16156
title: >-
  In PaperStream IP (TWAIN) 1.42.0.5685 (Service Update 7), the FJTWSVIC service
  running with SYSTEM privilege processes unauthenticated messages received over
  the FjtwMkic_Fjicube_32 named pipe
summary: >-
  In PaperStream IP (TWAIN) 1.42.0.5685 (Service Update 7), the FJTWSVIC service
  running with SYSTEM privilege processes unauthenticated messages received over
  the FjtwMkic_Fjicube_32 named pipe. One of these message processing functions
  a…
severity: high
cvss: 7.8
cvssVector: 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-426
vendor: fujitsu
product: paperstream_ip_(twain)
affected:
  - paperstream_ip_(twain) = 1.42.0.5685
published: '2019-05-17'
updated: '2026-10-08'
sourceUpdated: '2026-10-08T22:16:45.730'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2018-16156'
references:
  - url: >-
      http://packetstormsecurity.com/files/160832/PaperStream-IP-TWAIN-1.42.0.5685-Local-Privilege-Escalation.html
    label: cve@mitre.org
  - url: 'https://www.securifera.com/advisories/cve-2018-16156/'
    label: cve@mitre.org
  - url: >-
      http://packetstormsecurity.com/files/160832/PaperStream-IP-TWAIN-1.42.0.5685-Local-Privilege-Escalation.html
    label: af854a3a-2127-422b-91ae-364da2661108
  - url: 'https://www.securifera.com/advisories/cve-2018-16156/'
    label: af854a3a-2127-422b-91ae-364da2661108
tags:
  - nvd
  - exploit-available
epss: 0.02557
epssPercentile: 0.84606
exploits:
  exploitdb: true
  github: 1
  githubRepos:
    - 'https://github.com/securifera/CVE-2018-16156-Exploit'
  checkedAt: '2026-10-08T23:17:21.737Z'
exploitAvailable: true
ingestedAt: '2026-10-08T23:16:47.296Z'
---

## Overview

In PaperStream IP (TWAIN) 1.42.0.5685 (Service Update 7), the FJTWSVIC service running with SYSTEM privilege processes unauthenticated messages received over the FjtwMkic_Fjicube_32 named pipe. One of these message processing functions attempts to dynamically load the UninOldIS.dll library and executes an exported function named ChangeUninstallString. The default install does not contain this library and therefore if any DLL with that name exists in any directory listed in the PATH variable, it can be used to escalate to SYSTEM level privilege.

## Affected

- `paperstream_ip_(twain) = 1.42.0.5685`

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
