CVE Feed

    Dashboard / CVE / CVE-2025-34189

    CVE-2025-34189

    Vasion Print (formerly PrinterLogic) Virtual Appliance Host versions prior to 1.0.735 and Application versions prior to 20.0.1330 (macOS/Linux client deployments) contain a vulnerability in the local inter-process communication (IPC) mechanism. The software stores IPC request and response files inside /opt/PrinterInstallerClient/tmp with world-readable and world-writable permissions. Any local user can craft malicious request files that are processed by privileged daemons, leading to unauthorized actions being executed in other user sessions. This breaks user session isolation, potentially allowing local attackers to hijack sessions, perform unintended actions in the context of other users, and impact system integrity and availability. This vulnerability has been identified by the vendor as: V-2022-004 — Client Inter-process Security.

    Published:Sep 19, 2025
    Last Modified:Nov 17, 2025
    EPS:Sep 19, 2025
    EPSS Score:0.00015
    CVSS Score:7.8

    Affected Products

    Vendor
    Apple
    Product
    Macos
    Vendor
    Linux
    Product
    Linux Kernel
    Vendor
    Printerlogic
    Product
    Vasion Print
    Vendor
    Printerlogic
    Product
    Virtual Appliance
    Vendor
    Vasion
    Product
    Virtual Appliance Application
    Vendor
    Vasion
    Product
    Virtual Appliance Host

    Related CVEs

    Common Vulnerability Scoring System

    Attack Vector
    Network
    Adjacent
    Local
    Physical
    Privileges Required
    None
    Low
    High
    User Interaction
    None
    Required
    Scope
    Unchanged
    Changed
    Confidentiality
    None
    Low
    High
    Integrity
    None
    Low
    High
    Availability
    None
    Low
    High