CVE-2025-34193 Details
Description
Vasion Print (formerly PrinterLogic) Virtual Appliance Host versions prior to 25.1.102 and Application versions prior to 25.1.1413 include Windows client components (PrinterInstallerClientInterface.exe, PrinterInstallerClient.exe, PrinterInstallerClientLauncher.exe) that lack modern compile-time and runtime exploit mitigations and rely on outdated runtimes. These binaries are built as 32-bit, without Data Execution Prevention (DEP), Address Space Layout Randomization (ASLR), Control Flow Guard (CFG), or stack-protection, and they incorporate legacy technologies (Pascal/Delphi and Python 2) which are no longer commonly maintained. Several of these processes run with elevated privileges (NT AUTHORITY\SYSTEM for PrinterInstallerClient.exe and PrinterInstallerClientLauncher.exe), and the client automatically downloads and installs printer drivers. The absence of modern memory safety mitigations and the use of unmaintained runtimes substantially increase the risk that memory-corruption or other exploit primitives — for example from crafted driver content or maliciously crafted inputs — can be turned into remote or local code execution and privilege escalation to SYSTEM. This vulnerability has been confirmed to be remediated, but it is unclear as to when the patch was introduced.
A vulnerability exists in Vasion Print (formerly PrinterLogic) Windows client components included in the Virtual Appliance Host and Application. These components, which are built as 32-bit applications, lack essential modern compile-time and runtime exploit mitigations. They do not support Data Execution Prevention (DEP), Address Space Layout Randomization (ASLR), Control Flow Guard (CFG), or stack protection. Additionally, the binaries rely on outdated and unmaintained runtimes, including legacy technologies such as Pascal/Delphi and Python 2. Several processes within these components operate with elevated privileges, specifically NT AUTHORITY\SYSTEM, and automatically download and install printer drivers. The combination of missing contemporary memory safety protections, reliance on obsolete runtimes, and the potential for memory corruption from crafted driver content or malicious inputs significantly heightens the risk of remote or local code execution, with possible privilege escalation to SYSTEM.
Users can update the Vasion Windows Client to Version 25.0.0.897 or later. For the Virtual Appliance, update to Application build 20.0.1923 or later, which includes the updated Client version. If preferred, the new Windows Client can be pushed via third-party software using the Client installation package available from the Vasion Print Client Updates page.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Sep 19, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-1104 | Use of Unmaintained Third Party Components | [email protected] |
| CWE-755 | Improper Handling of Exceptional Conditions | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| vasion virtual appliance application | All versions |
CPE
Remediation
| |
| vasion virtual appliance host | All versions |
CPE
Remediation
| |
| microsoft windows | All versions |
CPE
Remediation
| |
Change History
5 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Sep 29, 2025 | CVE Modified | [email protected] |
| Sep 24, 2025 | Initial Analysis | [email protected] |
| Sep 19, 2025 | New CVE Received | [email protected] |