216.73.216.233

CVE-2025-34195

· Published 19/09/2025 19:15 · Modified 19/09/2025 19:15

Labels: CVE-2025-34195 2025-09-19CVE-2025-34195CWE-434[email protected]

Essential information

Published
19/09/2025 19:15
Modified
19/09/2025 19:15
Author
Creator
CVSS
8.6 HIGH (v3) 8.6 HIGH (v4.0)
CISA KEV
No
CWE
CVSS vector

CVSS metrics

Description

Vasion Print (formerly PrinterLogic) Virtual Appliance Host versions prior to 1.0.735 and Application prior to 20.0.1330 (Windows client deployments) contain a remote code execution vulnerability during driver installation caused by unquoted program paths. The PrinterInstallerClient driver-installation component launches programs using an unquoted path under "C:\Program Files (x86)\Printer Properties Pro\Printer Installer". Because the path is unquoted, the operating system may execute a program located at a short-path location such as C:\Program.exe before the intended binaries in the quoted path. If an attacker can place or cause a program to exist at that location, it will be executed with the privileges of the installer process (which may be elevated), enabling arbitrary code execution and potential privilege escalation. This weakness can be used to achieve remote code execution and full compromise of affected Windows endpoints.

NVD status

Status
Received — CVE has been recently published to the CVE List and has been received by the NVD.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
printerlogic / virtual appliance host cpe:2.3:a:printerlogic:virtual_appliance_host:<1.0.735:*:*:*:*:*:*
printerlogic / printer installer client cpe:2.3:a:printerlogic:printer_installer_client:<20.0.1330:*:*:*:*:*:*

References