High severity7.8NVD Advisory· Published Sep 29, 2025· Updated Jun 17, 2026
CVE-2025-34235
CVE-2025-34235
Description
Vasion Print (formerly PrinterLogic) Virtual Appliance Host prior to version 25.1.102 and Application prior to version 25.1.1413 (Windows client deployments) contain a registry key that can be enabled by administrators, causing the client to skip SSL/TLS certificate validation. An attacker who can intercept HTTPS traffic can then inject malicious driver DLLs, resulting in remote code execution with SYSTEM privileges; a local attacker can achieve local privilege escalation via a junction‑point DLL injection. This vulnerability has been confirmed to be remediated, but it is unclear as to when the patch was introduced.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
8<25.1.102+ 2 more
- (no CPE)range: <25.1.102
- (no CPE)range: *
- cpe:2.3:a:vasion:virtual_appliance_host:*:*:*:*:*:*:*:*range: <25.1.102
- Range: <25.1.1413
- Range: <25.1.1413
- Range: <25.1.102
- Range: *
- cpe:2.3:a:vasion:virtual_appliance_application:*:*:*:*:*:*:*:*Range: <25.1.1413
Patches
Vulnerability mechanics
References
4- pierrekim.github.io/blog/2025-04-08-vasion-printerlogic-83-vulnerabilities.htmlnvdExploitThird Party Advisory
- help.printerlogic.com/saas/Print/Security/Security-Bulletins.htmnvdVendor Advisory
- help.printerlogic.com/va/Print/Security/Security-Bulletins.htmnvdVendor Advisory
- www.vulncheck.com/advisories/vasion-print-printerlogic-weak-ssl-tls-certificate-validation-rcenvdThird Party Advisory
News mentions
0No linked articles in our index yet.