Multiple SEIKO EPSON printer drivers for Windows OS are configured with an improper access permission settings when installed or used in a language other than English. If a user is directed to place a crafted DLL file in a location of an attacker's choosing, the attacker may execute arbitrary code with SYSTEM privilege on a Windows system on which the printer driver is installed.
References
Configurations
No configuration.
History
29 Apr 2025, 13:52
Type | Values Removed | Values Added |
---|---|---|
Summary |
|
28 Apr 2025, 09:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2025-04-28 09:15
Updated : 2025-04-29 13:52
NVD link : CVE-2025-42598
Mitre link : CVE-2025-42598
CVE.ORG link : CVE-2025-42598
JSON object : View
Products Affected
No product.
CWE
CWE-276
Incorrect Default Permissions