PT-2025-38593 · Microsoft+1 · Windows+4

Pierre Barre

·

Published

2025-09-19

·

Updated

2025-09-29

·

CVE-2025-34193

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Vasion Print (formerly PrinterLogic) Virtual Appliance Host and Application
Description The Windows client components (PrinterInstallerClientInterface.exe, PrinterInstallerClient.exe, PrinterInstallerClientLauncher.exe) lack modern exploit mitigations such as Data Execution Prevention (DEP), Address Space Layout Randomization (ASLR), and Control Flow Guard (CFG). These components are built as 32-bit applications, without stack-protection, and utilize outdated technologies like Pascal/Delphi and Python 2. Several processes run with elevated privileges, and the client automatically downloads and installs printer drivers. The absence of these mitigations and the use of unmaintained runtimes increases the risk of remote or local code execution and privilege escalation to SYSTEM through memory corruption or maliciously crafted inputs.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

LPE

Improper Handling of Exceptional Conditions

Weakness Enumeration

Related Identifiers

CVE-2025-34193

Affected Products

Printerinstallerclient
Printerinstallerclientinterface.Exe
Printerinstallerclientlauncher.Exe
Vasion Print
Windows