CVE-2025-34189

Vasion Print (formerly PrinterLogic) Virtual Appliance Host versions prior to 1.0.735 and Application versions prior to 20.0.1330 (macOS/Linux client deployments) contain a vulnerability in the local inter-process communication (IPC) mechanism. The software stores IPC request and response files inside /opt/PrinterInstallerClient/tmp with world-readable and world-writable permissions. Any local user can craft malicious request files that are processed by privileged daemons, leading to unauthorized actions being executed in other user sessions. This breaks user session isolation, potentially allowing local attackers to hijack sessions, perform unintended actions in the context of other users, and impact system integrity and availability.
Configurations

Configuration 1 (hide)

AND
OR cpe:2.3:a:vasion:virtual_appliance_application:*:*:*:*:*:*:*:*
cpe:2.3:a:vasion:virtual_appliance_host:*:*:*:*:*:*:*:*
OR cpe:2.3:o:apple:macos:-:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*

History

24 Sep 2025, 19:28

Type Values Removed Values Added
References () https://help.printerlogic.com/saas/Print/Security/Security-Bulletins.htm - () https://help.printerlogic.com/saas/Print/Security/Security-Bulletins.htm - Vendor Advisory
References () https://help.printerlogic.com/va/Print/Security/Security-Bulletins.htm - () https://help.printerlogic.com/va/Print/Security/Security-Bulletins.htm - Vendor Advisory
References () https://pierrekim.github.io/blog/2025-04-08-vasion-printerlogic-83-vulnerabilities.html#mac-lack-auth-communication - () https://pierrekim.github.io/blog/2025-04-08-vasion-printerlogic-83-vulnerabilities.html#mac-lack-auth-communication - Exploit, Third Party Advisory
References () https://www.vulncheck.com/advisories/vasion-print-printerlogic-insecure-interprocess-communication - () https://www.vulncheck.com/advisories/vasion-print-printerlogic-insecure-interprocess-communication - Third Party Advisory
First Time Apple
Linux
Vasion
Vasion virtual Appliance Application
Apple macos
Linux linux Kernel
Vasion virtual Appliance Host
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.8
CPE cpe:2.3:a:vasion:virtual_appliance_host:*:*:*:*:*:*:*:*
cpe:2.3:o:apple:macos:-:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*
cpe:2.3:a:vasion:virtual_appliance_application:*:*:*:*:*:*:*:*

19 Sep 2025, 19:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-09-19 19:15

Updated : 2025-09-24 19:28


NVD link : CVE-2025-34189

Mitre link : CVE-2025-34189

CVE.ORG link : CVE-2025-34189


JSON object : View

Products Affected

vasion

  • virtual_appliance_host
  • virtual_appliance_application

apple

  • macos

linux

  • linux_kernel
CWE
CWE-732

Incorrect Permission Assignment for Critical Resource

CWE-922

Insecure Storage of Sensitive Information