PT-2025-38607 · Unknown · Vasion Print+1

Pierre Barre

·

Published

2025-09-19

·

Updated

2025-09-29

·

CVE-2025-34190

CVSS v4.0

8.5

High

VectorAV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Vasion Print (affected versions not specified)
Description Vasion Print Virtual Appliance Host and Application (macOS/Linux client deployments) are vulnerable to an authentication bypass in the PrinterInstallerClientService. The service’s checks for root privileges rely on calls to the geteuid() function. By preloading a malicious shared object overriding geteuid(), a local attacker can bypass authentication and execute administrative commands, such as enabling debug mode, managing configurations, or invoking privileged features, without proper authorization. This bypass breaks the intended security model of the inter-process communication (IPC) system, potentially allowing local attackers to escalate privileges and compromise system integrity.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

LPE

Missing Authentication

Weakness Enumeration

Related Identifiers

CVE-2025-34190

Affected Products

Vasion Print
Vasion Print Virtual Appliance