CVE-2025-34235: Vasion Virtual Appliance Application

High severity, CVSS 7.8. EPSS: 0.5% chance of exploitation in the next 30 days.

Vasion Print (formerly PrinterLogic) Virtual Appliance Host prior to version 25.1.102 and Application prior to version 25.1.1413 (Windows client deployments) contain a registry key that can be enabled by administrators, causing the client to skip SSL/TLS certificate validation. An attacker who can intercept HTTPS traffic can then inject malicious driver DLLs, resulting in remote code execution with SYSTEM privileges; a local attacker can achieve local privilege escalation via a junction‑point DLL injection. This vulnerability has been confirmed to be remediated, but it is unclear as to when the patch was introduced.

Affected products

  • Vasion Virtual Appliance Application: before 25.1.1413 (fixed in 25.1.1413)
  • Vasion Virtual Appliance Host: before 25.1.102 (fixed in 25.1.102)

Published 2025-09-29. Last modified 2026-06-17.