7.8

CVE-2020-5674

Untrusted search path vulnerability in the installers of multiple SEIKO EPSON products allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Epson ≫ Album Print Version - SwPlatform update_program
Epson ≫ Colorbase Version -
Epson ≫ Colorio Easy Print Version -
Epson ≫ Connect Version -
Epson ≫ Creativity Suite Version -
Epson ≫ E-photo Version - SwPlatform camera_raw
Epson ≫ E-photo Version - SwPlatform picture_motion_browser
Epson ≫ Easy Photo Print Version - SwPlatform -
Epson ≫ Easy Photo Print Version - SwPlatform camera_raw
Epson ≫ Easy Settings Version - SwPlatform office
Epson ≫ Imaging Workshop Version -
Epson ≫ Link2 Version -
Epson ≫ Multi-print Quicker Version - SwPlatform windows
Epson ≫ Net Config Version -
Epson ≫ Net Config Se Version -
Epson ≫ Net Print Version -
Epson ≫ Photolier Version -
Epson ≫ Photoquicker Version -
Epson ≫ Photostarter Version 3.1
Epson ≫ Pm-t990 Integrated Installer Version - SwPlatform windows
Epson ≫ Print Version - SwPlatform playmemories_home
Epson ≫ Print Version - SwPlatform silkypix
Epson ≫ Print Version - SwPlatform viewnx
Epson ≫ Print Layout Version - SwPlatform photoshop
Epson ≫ Prolab Print Version -
Epson ≫ Prolab Print Version - SwPlatform camera_raw
Epson ≫ Scan Icm Updater Version -
Epson ≫ Scanner Driver Version -
Epson ≫ Web To Page Version -
Epson ≫ Webconfig Version -
Epson ≫ Universal Print Driver Version -
   Microsoft ≫ Windows Version - HwPlatform x64
   Microsoft ≫ Windows Version - HwPlatform x86
Epson ≫ Status Monitor 2 Version -
   Microsoft ≫ Windows Version -
Epson ≫ Status Monitor 3 Version -
   Microsoft ≫ Windows Version -
Epson ≫ Ec-01 Firmware Version -
   Epson ≫ Ec-01 Version -
Epson ≫ Print Image Framer Tool Version -
   Microsoft ≫ Windows 98 Version -
   Microsoft ≫ Windows Me Version -
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 0.35% 0.276
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 7.8 1.8 5.9
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
NIST 4.4 3.4 6.4
AV:L/AC:M/Au:N/C:P/I:P/A:P
CWE-427 Uncontrolled Search Path Element

The product uses a fixed or controlled search path to find resources, but one or more locations in that path can be under the control of unintended actors.

https://jvn.jp/en/jp/JVN26835001/index.html
Third Party Advisory
https://www.epson.jp/support/misc_t/201119_oshirase.htm
Vendor Advisory
https://www.epson.jp/support/pdf/fy20-001_softwareList_20201106_b.pdf
Vendor Advisory