πŸ›‘οΈ CVE-2025-34191
🟠 CVSS 8.4 β€” High ⚠️ Exploit Public CWE-59 NVD
8.4
CVSS Score
0 Low4 Medium7 High9 Critical10

Description

Vasion Print (formerly PrinterLogic) Virtual Appliance Host versions prior to 22.0.843 and Application prior to 20.0.1923 (macOS/Linux client deployments) contain an arbitrary file write vulnerability via the response file handling. When tasks produce output the service writes response data into files under /opt/PrinterInstallerClient/tmp/responses/ reusing the requested filename. The service follows symbolic links in the responses directory and writes as the service user (typically root), allowing a local, unprivileged user to cause the service to overwrite or create arbitrary files on the filesystem as root. This can be used to modify configuration files, replace or inject binaries or drivers, and otherwise achieve local privilege escalation and full system compromise.Β This vulnerability has been identified by the vendor as: V-2023-019 β€” Arbitrary File Write as Root.

Details

Severity HIGH
CVSS Score 8.4
CVSS Vector CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
CWE CWE-59
Public Exploit ⚠️ Yes
Source NVD
Published 2025-09-19
Updated 2026-06-02
Modified 2025-10-02
Fix URL N/A

Affected Packages

Software From version Fixed in
virtual-appliance-application β€” 20.0.1923
virtual-appliance-host β€” 22.0.843

Similar Threats

Site Security Check

Concerned your site may already be targeted?

BotEraser analyzes incoming traffic patterns and helps identify bot behavior consistent with known exploit attempts.

Check My Site Free β†’

No credit card required  Β·  Results in minutes

ⓘ Data Notice: The information presented above has been compiled from publicly available internet sources. Boteraser aggregates this data solely for informational purposes and does not independently classify, evaluate, or endorse any findings about the vulnerabilities listed. The accuracy and completeness of this information is the sole responsibility of the original publishers. Boteraser and its operators accept no liability for any decisions made based on this data.