cvedb.io
CVE-2025-34195
CRITICAL · CVSS 9.8
EPSS exploitation probability: 0%
Published 2025-09-19T19:15:40.123 · Last modified 2026-06-17T09:13:37.997

Summary

Vasion Print (formerly PrinterLogic) Virtual Appliance Host versions prior to 1.0.735 and Application prior to 20.0.1330 (Windows client deployments) contain a remote code execution vulnerability during driver installation caused by unquoted program paths. The PrinterInstallerClient driver-installation component launches programs using an unquoted path under "C:\Program Files (x86)\Printer Properties Pro\Printer Installer". Because the path is unquoted, the operating system may execute a program located at a short-path location such as C:\Program.exe before the intended binaries in the quoted path. If an attacker can place or cause a program to exist at that location, it will be executed with the privileges of the installer process (which may be elevated), enabling arbitrary code execution

Affected products

vasion — virtual_appliance_application

Does this affect you?

Add your gear to cvedb and we'll alert you only when vasion ships something exploited.

Check my exposure →

References

This product uses data from the NVD API but is not endorsed or certified by the NVD. Informational only; not professional security advice.