Multiple SEIKO EPSON printer drivers for Windows OS are configured with an improper access permission settings when installed or used in a language other than English. If a user is directed to place a crafted DLL file in a location of an attacker's choosing, the attacker may execute arbitrary code with SYSTEM privilege on a Windows system on which the printer driver is installed.
Metrics
Affected Vendors & Products
References
History
Mon, 28 Apr 2025 16:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Mon, 28 Apr 2025 08:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | Multiple SEIKO EPSON printer drivers for Windows OS are configured with an improper access permission settings when installed or used in a language other than English. If a user is directed to place a crafted DLL file in a location of an attacker's choosing, the attacker may execute arbitrary code with SYSTEM privilege on a Windows system on which the printer driver is installed. | |
Weaknesses | CWE-276 | |
References |
| |
Metrics |
cvssV3_1
|

Status: PUBLISHED
Assigner: jpcert
Published: 2025-04-28T08:20:56.756Z
Updated: 2025-04-28T16:10:51.558Z
Reserved: 2025-04-16T11:56:26.983Z
Link: CVE-2025-42598

Updated: 2025-04-28T16:10:32.608Z

Status : Awaiting Analysis
Published: 2025-04-28T09:15:21.557
Modified: 2025-04-29T13:52:10.697
Link: CVE-2025-42598

No data.