Untrusted search path vulnerability in the installers of multiple SEIKO EPSON products allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory.
References
Link | Resource |
---|---|
https://www.epson.jp/support/pdf/fy20-001_softwareList_20201106_b.pdf | Vendor Advisory |
https://www.epson.jp/support/misc_t/201119_oshirase.htm | Vendor Advisory |
https://jvn.jp/en/jp/JVN26835001/index.html | Third Party Advisory |
Configurations
Configuration 1 (hide)
|
Configuration 2 (hide)
AND |
|
Configuration 3 (hide)
AND |
|
Configuration 4 (hide)
AND |
|
Configuration 5 (hide)
AND |
|
Information
Published : 2020-11-23 23:15
Updated : 2021-07-21 04:39
NVD link : CVE-2020-5674
Mitre link : CVE-2020-5674
JSON object : View
CWE
CWE-427
Uncontrolled Search Path Element
Products Affected
epson
- colorio_easy_print
- net_software_development_kit
- net_config
- easy_photo_print
- webconfig
- imaging_workshop
- scan_icm_updater
- photoquicker
- status_monitor_3
- connect
- print_layout
- easy_settings
- creativity_suite
- e-photo
- photolier
- album_print
- net_print
- color_calibration_utility
- pm-t990_integrated_installer
- status_monitor_2
- ec-01_firmware
- link2
- remote_printer_driver
- print_image_framer_tool
- photostarter
- multi-print_quicker
- universal_print_driver
- scanner_driver
- colorbase
- prolab_print
- net_config_se
- web_to_page
- ec-01
microsoft
- windows_98
- windows
- windows_me