We use these services and cookies to improve your user experience. You may opt out if you wish, however, this may limit some features on this site.

Please see our statement on Data Privacy.

Crisp.chat (Helpdesk and Chat)

Ok

THREATINT
PUBLISHED

CVE-2025-42598



Description

Multiple SEIKO EPSON printer drivers for Windows OS are configured with an improper access permission settings when installed or used in a language other than English. If a user is directed to place a crafted DLL file in a location of an attacker's choosing, the attacker may execute arbitrary code with SYSTEM privilege on a Windows system on which the printer driver is installed.

Reserved 2025-04-16 | Published 2025-04-28 | Updated 2025-04-28 | Assigner jpcert


HIGH: 7.8CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

HIGH: 8.4CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N

Problem types

Incorrect default permissions

Product status

see the information provided by SEIKO EPSON CORPORATION.
affected

References

www.epson.co.uk/en_GB/faq/KA-01993/contents?loc=en-us

www.epson.jp/support/misc_t/250428_oshirase.htm

www2.epson.jp/support/misc_t/windrv_productlist.pdf

jvn.jp/en/vu/JVNVU90649144/

cve.org (CVE-2025-42598)

nvd.nist.gov (CVE-2025-42598)

Download JSON

Share this page
https://cve.threatint.eu/CVE/CVE-2025-42598

Support options

Helpdesk Chat, Email, Knowledgebase