CVE-2025-34193: CWE-755 Improper Handling of Exceptional Conditions in Vasion Print Virtual Appliance Host
Vasion Print (formerly PrinterLogic) Virtual Appliance Host versions prior to 25.1.102 and Application versions prior to 25.1.1413 include Windows client components (PrinterInstallerClientInterface.exe, PrinterInstallerClient.exe, PrinterInstallerClientLauncher.exe) that lack modern compile-time and runtime exploit mitigations and rely on outdated runtimes. These binaries are built as 32-bit, without Data Execution Prevention (DEP), Address Space Layout Randomization (ASLR), Control Flow Guard (CFG), or stack-protection, and they incorporate legacy technologies (Pascal/Delphi and Python 2) which are no longer commonly maintained. Several of these processes run with elevated privileges (NT AUTHORITY\SYSTEM for PrinterInstallerClient.exe and PrinterInstallerClientLauncher.exe), and the client automatically downloads and installs printer drivers. The absence of modern memory safety mitigations and the use of unmaintained runtimes substantially increase the risk that memory-corruption or other exploit primitives — for example from crafted driver content or maliciously crafted inputs — can be turned into remote or local code execution and privilege escalation to SYSTEM. This vulnerability has been confirmed to be remediated, but it is unclear as to when the patch was introduced.
AI Analysis
Technical Summary
Vasion Print Virtual Appliance Host prior to version 25.1.102 and Application versions prior to 25.1.1413 include 32-bit Windows client binaries lacking modern memory safety mitigations (DEP, ASLR, CFG, stack protection) and use legacy runtimes (Pascal/Delphi, Python 2). Several of these processes run with NT AUTHORITY\SYSTEM privileges and automatically download and install printer drivers. The absence of exploit mitigations combined with elevated privileges and legacy code increases the likelihood that memory corruption or other exploit primitives from crafted driver content or malicious inputs could lead to remote or local code execution and privilege escalation to SYSTEM. The vulnerability is tracked as CWE-755 (Improper Handling of Exceptional Conditions) and CWE-1104 (Use of Unmaintained Third Party Components). Although the patch date is not specified, the vulnerability is confirmed remediated.
Potential Impact
Successful exploitation could allow an attacker to achieve local or remote code execution with SYSTEM privileges on affected Vasion Print Virtual Appliance Hosts. This could enable full control over the host system, including installing malicious drivers or executing arbitrary code. The lack of modern exploit mitigations and use of outdated runtimes significantly increase the risk of exploitation. No known exploits in the wild have been reported to date.
Mitigation Recommendations
The vulnerability has been confirmed as remediated by the vendor, though the exact patch introduction date is not specified. Users should ensure they are running Vasion Print Virtual Appliance Host version 25.1.102 or later and Application version 25.1.1413 or later to benefit from the fix. Since this is not a cloud service, remediation requires updating the affected software to the fixed versions. Patch status beyond this confirmation is not explicitly detailed; users should consult Vasion's official advisories for the latest remediation guidance.
CVE-2025-34193: CWE-755 Improper Handling of Exceptional Conditions in Vasion Print Virtual Appliance Host
Description
Vasion Print (formerly PrinterLogic) Virtual Appliance Host versions prior to 25.1.102 and Application versions prior to 25.1.1413 include Windows client components (PrinterInstallerClientInterface.exe, PrinterInstallerClient.exe, PrinterInstallerClientLauncher.exe) that lack modern compile-time and runtime exploit mitigations and rely on outdated runtimes. These binaries are built as 32-bit, without Data Execution Prevention (DEP), Address Space Layout Randomization (ASLR), Control Flow Guard (CFG), or stack-protection, and they incorporate legacy technologies (Pascal/Delphi and Python 2) which are no longer commonly maintained. Several of these processes run with elevated privileges (NT AUTHORITY\SYSTEM for PrinterInstallerClient.exe and PrinterInstallerClientLauncher.exe), and the client automatically downloads and installs printer drivers. The absence of modern memory safety mitigations and the use of unmaintained runtimes substantially increase the risk that memory-corruption or other exploit primitives — for example from crafted driver content or maliciously crafted inputs — can be turned into remote or local code execution and privilege escalation to SYSTEM. This vulnerability has been confirmed to be remediated, but it is unclear as to when the patch was introduced.
CVSS v4.0
Score 7.1high
Affected software
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
Vasion Print Virtual Appliance Host prior to version 25.1.102 and Application versions prior to 25.1.1413 include 32-bit Windows client binaries lacking modern memory safety mitigations (DEP, ASLR, CFG, stack protection) and use legacy runtimes (Pascal/Delphi, Python 2). Several of these processes run with NT AUTHORITY\SYSTEM privileges and automatically download and install printer drivers. The absence of exploit mitigations combined with elevated privileges and legacy code increases the likelihood that memory corruption or other exploit primitives from crafted driver content or malicious inputs could lead to remote or local code execution and privilege escalation to SYSTEM. The vulnerability is tracked as CWE-755 (Improper Handling of Exceptional Conditions) and CWE-1104 (Use of Unmaintained Third Party Components). Although the patch date is not specified, the vulnerability is confirmed remediated.
Potential Impact
Successful exploitation could allow an attacker to achieve local or remote code execution with SYSTEM privileges on affected Vasion Print Virtual Appliance Hosts. This could enable full control over the host system, including installing malicious drivers or executing arbitrary code. The lack of modern exploit mitigations and use of outdated runtimes significantly increase the risk of exploitation. No known exploits in the wild have been reported to date.
Mitigation Recommendations
The vulnerability has been confirmed as remediated by the vendor, though the exact patch introduction date is not specified. Users should ensure they are running Vasion Print Virtual Appliance Host version 25.1.102 or later and Application version 25.1.1413 or later to benefit from the fix. Since this is not a cloud service, remediation requires updating the affected software to the fixed versions. Patch status beyond this confirmation is not explicitly detailed; users should consult Vasion's official advisories for the latest remediation guidance.
Technical Details
- Data Version
- 5.1
- Assigner Short Name
- VulnCheck
- Date Reserved
- 2025-04-15T19:15:22.569Z
- Cvss Version
- 4.0
- State
- PUBLISHED
Threat ID: 68cda6a24b8a032c4fac76ec
Added to database: 09/19/2025, 18:53:22 UTC
Last enriched: 05/16/2026, 09:19:20 UTC
Last updated: 09/10/2026, 19:36:50 UTC
Views: 196
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.