Vulnerability Description
Untrusted search path vulnerability in the installers of multiple SEIKO EPSON products allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Epson | Album Print | - |
| Epson | Color Calibration Utility | - |
| Epson | Colorbase | - |
| Epson | Colorio Easy Print | - |
| Epson | Connect | - |
| Epson | Creativity Suite | - |
| Epson | E-Photo | - |
| Epson | Easy Photo Print | - |
| Epson | Easy Settings | - |
| Epson | Imaging Workshop | - |
| Epson | Link2 | - |
| Epson | Multi-Print Quicker | - |
| Epson | Net Config | - |
| Epson | Net Config Se | - |
| Epson | Net Print | - |
| Epson | Net Software Development Kit | - |
| Epson | Photolier | - |
| Epson | Photoquicker | - |
| Epson | Photostarter | 3.1 |
| Epson | Pm-T990 Integrated Installer | - |
Related Weaknesses (CWE)
References
- https://jvn.jp/en/jp/JVN26835001/index.htmlThird Party Advisory
- https://www.epson.jp/support/misc_t/201119_oshirase.htmVendor Advisory
- https://www.epson.jp/support/pdf/fy20-001_softwareList_20201106_b.pdfVendor Advisory
- https://jvn.jp/en/jp/JVN26835001/index.htmlThird Party Advisory
- https://www.epson.jp/support/misc_t/201119_oshirase.htmVendor Advisory
- https://www.epson.jp/support/pdf/fy20-001_softwareList_20201106_b.pdfVendor Advisory
FAQ
What is CVE-2020-5674?
CVE-2020-5674 is a vulnerability with a CVSS score of 7.8 (HIGH). Untrusted search path vulnerability in the installers of multiple SEIKO EPSON products allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory.
How severe is CVE-2020-5674?
CVE-2020-5674 has been rated HIGH with a CVSS base score of 7.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2020-5674?
Check the references section above for vendor advisories and patch information. Affected products include: Epson Album Print, Epson Color Calibration Utility, Epson Colorbase, Epson Colorio Easy Print, Epson Connect.