Skip to main content
EPSS 0.8%top 46%

CVE-2025-34193: CWE-755 Improper Handling of Exceptional Conditions in Vasion Print Virtual Appliance Host

0
High
VulnerabilityCVE-2025-34193cvecve-2025-34193cwe-755cwe-1104
Published: 09/19/2025 (09/19/2025, 18:47:35 UTC)
Source: CVE Database V5
Vendor/Project: Vasion
Product: Print Virtual Appliance Host

Description

Vasion Print (formerly PrinterLogic) Virtual Appliance Host versions prior to 25.1.102 and Application versions prior to 25.1.1413 include Windows client components (PrinterInstallerClientInterface.exe, PrinterInstallerClient.exe, PrinterInstallerClientLauncher.exe) that lack modern compile-time and runtime exploit mitigations and rely on outdated runtimes. These binaries are built as 32-bit, without Data Execution Prevention (DEP), Address Space Layout Randomization (ASLR), Control Flow Guard (CFG), or stack-protection, and they incorporate legacy technologies (Pascal/Delphi and Python 2) which are no longer commonly maintained. Several of these processes run with elevated privileges (NT AUTHORITY\SYSTEM for PrinterInstallerClient.exe and PrinterInstallerClientLauncher.exe), and the client automatically downloads and installs printer drivers. The absence of modern memory safety mitigations and the use of unmaintained runtimes substantially increase the risk that memory-corruption or other exploit primitives — for example from crafted driver content or maliciously crafted inputs — can be turned into remote or local code execution and privilege escalation to SYSTEM. This vulnerability has been confirmed to be remediated, but it is unclear as to when the patch was introduced.

CVSS v4.0

Score 7.1high

Attack Vector
Local
Attack Complexity
Low
Attack Requirements
None
Privileges Required
None
User Interaction
None
Vuln. Confidentiality
Low
Vuln. Integrity
High
Vuln. Availability
High
Subsq. Confidentiality
None
Subsq. Integrity
None
Subsq. Availability
None
CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:L/VI:H/VA:H/SC:N/SI:N/SA:N

Affected software

Affected versions
=0

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 05/16/2026, 09:19:20 UTC

Technical Analysis

Vasion Print Virtual Appliance Host prior to version 25.1.102 and Application versions prior to 25.1.1413 include 32-bit Windows client binaries lacking modern memory safety mitigations (DEP, ASLR, CFG, stack protection) and use legacy runtimes (Pascal/Delphi, Python 2). Several of these processes run with NT AUTHORITY\SYSTEM privileges and automatically download and install printer drivers. The absence of exploit mitigations combined with elevated privileges and legacy code increases the likelihood that memory corruption or other exploit primitives from crafted driver content or malicious inputs could lead to remote or local code execution and privilege escalation to SYSTEM. The vulnerability is tracked as CWE-755 (Improper Handling of Exceptional Conditions) and CWE-1104 (Use of Unmaintained Third Party Components). Although the patch date is not specified, the vulnerability is confirmed remediated.

Potential Impact

Successful exploitation could allow an attacker to achieve local or remote code execution with SYSTEM privileges on affected Vasion Print Virtual Appliance Hosts. This could enable full control over the host system, including installing malicious drivers or executing arbitrary code. The lack of modern exploit mitigations and use of outdated runtimes significantly increase the risk of exploitation. No known exploits in the wild have been reported to date.

Mitigation Recommendations

The vulnerability has been confirmed as remediated by the vendor, though the exact patch introduction date is not specified. Users should ensure they are running Vasion Print Virtual Appliance Host version 25.1.102 or later and Application version 25.1.1413 or later to benefit from the fix. Since this is not a cloud service, remediation requires updating the affected software to the fixed versions. Patch status beyond this confirmation is not explicitly detailed; users should consult Vasion's official advisories for the latest remediation guidance.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Data Version
5.1
Assigner Short Name
VulnCheck
Date Reserved
2025-04-15T19:15:22.569Z
Cvss Version
4.0
State
PUBLISHED

Threat ID: 68cda6a24b8a032c4fac76ec

Added to database: 09/19/2025, 18:53:22 UTC

Last enriched: 05/16/2026, 09:19:20 UTC

Last updated: 09/10/2026, 19:36:50 UTC

Views: 196

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses