PT-2025-38607 · Unknown · Vasion Print+1
Pierre Barre
·
Published
2025-09-19
·
Updated
2025-09-29
·
CVE-2025-34190
CVSS v4.0
8.5
High
| Vector | AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
Vasion Print (affected versions not specified)
Description
Vasion Print Virtual Appliance Host and Application (macOS/Linux client deployments) are vulnerable to an authentication bypass in the
PrinterInstallerClientService. The service’s checks for root privileges rely on calls to the geteuid() function. By preloading a malicious shared object overriding geteuid(), a local attacker can bypass authentication and execute administrative commands, such as enabling debug mode, managing configurations, or invoking privileged features, without proper authorization. This bypass breaks the intended security model of the inter-process communication (IPC) system, potentially allowing local attackers to escalate privileges and compromise system integrity.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
LPE
Missing Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Vasion Print
Vasion Print Virtual Appliance