CVE-2020-5674

HIGHCVSS 7.8/10EPSS 0.34%

Last modified

CVE-2020-5674 is a high-severity vulnerability rated 7.8/10 on the CVSS scale. Untrusted search path vulnerability in the installers of multiple SEIKO EPSON products allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory.. EPSS estimates a 0.34% chance of exploitation in the next 30 days.

Description

Untrusted search path vulnerability in the installers of multiple SEIKO EPSON products allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory.

Metrics

CVSS 3.1
7.8/10

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

EPSS Probability
0.34%

26.2th percentile

Probability of exploitation in the next 30 days. Learn more

Weakness Enumeration

Affected Software

VendorProductVersions
EpsonAlbum PrintAll versions
EpsonColor Calibration UtilityAll versions
EpsonColorbaseAll versions
EpsonColorio Easy PrintAll versions
EpsonConnectAll versions
EpsonCreativity SuiteAll versions
EpsonE-PhotoAll versions
EpsonEasy Photo PrintAll versions
EpsonEasy SettingsAll versions
EpsonImaging WorkshopAll versions
EpsonLink2All versions
EpsonMulti-Print QuickerAll versions
EpsonNet ConfigAll versions
EpsonNet Config SeAll versions
EpsonNet PrintAll versions
EpsonNet Software Development KitAll versions
EpsonPhotolierAll versions
EpsonPhotoquickerAll versions
EpsonPhotostarter3.1
EpsonPm-T990 Integrated InstallerAll versions
EpsonPrintAll versions
EpsonPrint Image Framer ToolAll versions
EpsonPrint LayoutAll versions
EpsonProlab PrintAll versions
EpsonRemote Printer DriverAll versions
EpsonScan Icm UpdaterAll versions
EpsonScanner DriverAll versions
EpsonWeb To PageAll versions
EpsonWebconfigAll versions
EpsonUniversal Print DriverAll versions
EpsonStatus Monitor 2All versions
EpsonStatus Monitor 3All versions
EpsonEc-01 FirmwareAll versions

References

Timeline

Published
Last Modified
Status
Modified

Frequently Asked Questions

What is CVE-2020-5674?
Untrusted search path vulnerability in the installers of multiple SEIKO EPSON products allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory.
How severe is CVE-2020-5674?
CVE-2020-5674 has a CVSS score of 7.8/10 (HIGH severity). The EPSS model estimates a 0.34% probability of exploitation in the next 30 days.
How do I fix CVE-2020-5674?
Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also run a Strix scan to test if your systems are affected.

Are you affected by CVE-2020-5674?

Run a free Strix scan to check your systems for this vulnerability.

Scan your code now

Source: NVD / NIST