Untrusted Search Path Vulnerability in Epson Networking Software
CVE-2020-5681

7.8HIGH

What is CVE-2020-5681?

A vulnerability affecting self-extracting files created by EpsonNet SetupManager and Offirio SynergyWare PrintDirector allows malicious actors to exploit untrusted search paths. By placing a Trojan horse DLL in an unspecified directory, attackers can gain elevated privileges, compromising system security and data integrity. Users are urged to update to the latest versions of these applications to mitigate potential risks.

Affected Version(s)

EpsonNet SetupManager and Offirio SynergyWare PrintDirector EpsonNet SetupManager versions 2.2.14 and earlier, and Offirio SynergyWare PrintDirector versions 1.6x/1.6y and earlier

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.