CVE-2010-3920

Severity CVSS v4.0:
Pending analysis
Type:
CWE-264 Permissions, Privileges, and Access Control
Publication date:
08/12/2010
Last modified:
11/04/2025

Description

The Seiko Epson printer driver installers for LP-S9000 before 4.1.11 and LP-S7100 before 4.1.7, or as downloaded from the vendor between May 2010 and 20101125, set weak permissions for the "C:\Program Files" folder, which might allow local users to bypass intended access restrictions and create or modify arbitrary files and directories.

Vulnerable products and versions

CPE From Up to
cpe:2.3:h:epson:lp-s7100:*:*:*:*:*:*:*:*
cpe:2.3:a:epson:lp-s7100_driver_4.1.0:*:*:*:*:*:*:*:*
cpe:2.3:a:epson:lp-s7100_driver_4.1.7:*:*:*:*:*:*:*:*
cpe:2.3:h:epson:lp-s9000:*:*:*:*:*:*:*:*
cpe:2.3:a:epson:lp-s9000_driver_4.1.0:*:*:*:*:*:*:*:*
cpe:2.3:a:epson:lp-s9000_driver_4.1.11:*:*:*:*:*:*:*:*