Elevated Privilege Vulnerability in Vasion Print by Vasion
CVE-2025-34193

7.1HIGH

Key Information:

Vendor

Vasion

Vendor
CVE Published:
19 September 2025

What is CVE-2025-34193?

The Vasion Print Virtual Appliance products, including both the Host and Application, contain Windows client components that lack modern compile-time and runtime protections such as Data Execution Prevention (DEP) and Address Space Layout Randomization (ASLR). Built as 32-bit applications, they utilize outdated technologies like Pascal/Delphi and Python 2, raising security concerns due to their reliance on unmaintained runtimes. Several components operate with elevated privileges, making them susceptible to risks of memory corruption. This vulnerability facilitates potential exploit vectors, enabling local and remote code execution, which significantly undermines system security.

Affected Version(s)

Print Application Windows *

Print Virtual Appliance Host Windows *

References

CVSS V4

Score:
7.1
Severity:
HIGH
Confidentiality:
Low
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Pierre Barre
.
CVE-2025-34193 : Elevated Privilege Vulnerability in Vasion Print by Vasion