CVE-2020-5674
7.8
Vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Exploitability: 1.8 / Impact: 5.9
Source: NVD
Description
Untrusted search path vulnerability in the installers of multiple SEIKO EPSON products allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory.
Affected (38)
Products: Epson: Album Print, Color Calibration Utility, Colorbase, Colorio Easy Print, Connect, Creativity Suite, E Photo, Easy Photo Print, Easy Settings, Imaging Workshop, Link2, Multi Print Quicker, Net Config, Net Config Se, Net Print, Net Software Development Kit, Photolier, Photoquicker, Photostarter, Pm T990 Integrated Installer, Print, Print Layout, Prolab Print, Remote Printer Driver, Scan Icm Updater, Scanner Driver, Web To Page, Webconfig, Universal Print Driver, Status Monitor 2, Status Monitor 3, Ec 01 Firmware, Print Image Framer Tool
Configuration A
| Vulnerable Software | Affected Versions |
|---|---|
| All versions | |
| All versions | |
| All versions | |
| All versions | |
| All versions | |
| All versions | |
| All versions | |
| All versions | |
| All versions | |
| All versions | |
| All versions | |
| All versions | |
| All versions | |
| All versions | |
| All versions | |
| All versions | |
| All versions | |
| All versions | |
| Version 3.1 | |
| All versions | |
| All versions | |
| All versions | |
| All versions | |
| All versions | |
| All versions | |
| All versions | |
| All versions | |
| All versions |
Configuration B
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Microsoft Windows | All versions |
Configuration C
| Vulnerable Software | Affected Versions |
|---|---|
| All versions | |
| All versions |
| Running on/with | Platform Versions |
|---|---|
Microsoft Windows | All versions |
Configuration D
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Epson Ec 01 | All versions |
Configuration E
| Vulnerable Software | Affected Versions |
|---|---|
| All versions |
| Running on/with | Platform Versions |
|---|---|
Microsoft Windows 98 | All versions |
Microsoft Windows Me | All versions |
References (6)
Source: vultures@jpcert.or.jp
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Third Party Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Source: af854a3a-2127-422b-91ae-364da2661108
Vendor Advisory
Timeline
No history available yet.