First published: Mon Apr 28 2025(Updated: )
Multiple SEIKO EPSON printer drivers for Windows OS are configured with an improper access permission settings when installed or used in a language other than English. If a user is directed to place a crafted DLL file in a location of an attacker's choosing, the attacker may execute arbitrary code with SYSTEM privilege on a Windows system on which the printer driver is installed.
Credit: vultures@jpcert.or.jp
Affected Software | Affected Version | How to fix |
---|---|---|
SEIKO EPSON printer drivers |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-42598 is considered a high severity vulnerability due to improper access permissions in SEIKO EPSON printer drivers.
To fix CVE-2025-42598, ensure that the printer drivers are updated to the latest version from the SEIKO EPSON website, which addresses the access permission issues.
Users of SEIKO EPSON printer drivers on Windows OS who install or use the drivers in languages other than English are affected by CVE-2025-42598.
CVE-2025-42598 is a code execution vulnerability that allows an attacker to execute arbitrary code through crafted DLL files due to improper permissions.
If affected by CVE-2025-42598, you should immediately update your printer drivers and scan your system for any unauthorized changes or malware.