CVE-2020-5674
moderate-risk
Published 2020-11-24
Untrusted search path vulnerability in the installers of multiple SEIKO EPSON products allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory.
Do I need to act?
-
0.08% chance of exploitation
EPSS score — low exploit probability
-
Not on CISA KEV list
No confirmed active exploitation reported to CISA
?
Patch status unknown
Check vendor advisories for fix availability and mitigation guidance
7
CVSS 7.8/10
High
LOCAL
/ LOW complexity
Affected Products (20)
Album Print
Color Calibration Utility
Colorbase
Colorio Easy Print
Connect
Creativity Suite
E-Photo
E-Photo
Easy Photo Print
Easy Photo Print
Easy Settings
Imaging Workshop
Link2
Multi-Print Quicker
Net Config
Net Config Se
Net Print
Net Software Development Kit
Photolier
Photoquicker
Affected Vendors
References (6)
Third Party Advisory
https://jvn.jp/en/jp/JVN26835001/index.html
Vendor Advisory
https://www.epson.jp/support/misc_t/201119_oshirase.htm
Third Party Advisory
https://jvn.jp/en/jp/JVN26835001/index.html
Vendor Advisory
https://www.epson.jp/support/misc_t/201119_oshirase.htm
48
/ 100
moderate-risk
Severity
24/34 · High
Exploitability
0/34 · Minimal
Exposure
24/34 · High