Epson Printer Driver Vulnerability CVE-2025-42598: How to Fix

By Silke Kluckert on May 20, 2025
Last updated on September 22, 2026

Epson Printer Driver Vulnerability: What IT Admins Need to Do

Updated on September 22, 2026

CVE-2025-42598 is a high-severity privilege-escalation vulnerability affecting a wide range of Epson printer drivers for Windows when they are installed or used in a non-English language environment. The vulnerability is caused by incorrect access permissions and can allow an attacker to execute arbitrary code with SYSTEM privileges under specific conditions.

Epson has released a security update and currently reports no known attacks exploiting the vulnerability. Organizations using Epson printer drivers on Windows should nevertheless verify that the appropriate security update has been deployed.

Current Status - Checked Sept. 22, 2026
Details
Status
Security update available; affected installations should be remediated.
Severity
High - CVSS 8.4 (v4.0) / 7.8 (v3.1)
Affected Environment
Epson Windows printer drivers installed or used in a language environment other than English
Potential Impact
Local privilege escalation and arbitrary code execution with SYSTEM privileges
Known Exploitation
Epson currently reports no known attacks exploiting CVE-2025-42598
Recommended Action
Run Epson Software Updater and install the latest Epson Printer Driver Security Support Tool, or obtain the security patch from the appropriate Epson product support page.

 

What is CVE-2025-42598?

CVE-2025-32598 is a security vulnerability caused by incorrect access-permission settings in multiple Epson printer drivers for Windows.

According to JVN/JPCERT, affected drivers can be configured with improper permissions when installed or used in a language other than English. The vulnerability is classified as CWE-276: Incorrect Default Permissions.

Its severity is rated:

  • CVSS 4.0: 8.4 — High
  • CVSS 3.1: 7.8 — High

Successful exploitation may allow an attacker to execute arbitrary code with SYSTEM privileges on a Windows computer on which an affected printer driver is installed.

Importantly, CVE-2025-42598 is classified as a local vulnerability, not a remotely exploitable network vulnerability. User interaction is required for the documented attack scenario.

Which Epson Printer Drivers Are Affected?

The vulnerability affects a wide range of Epson Windows printer drivers when they are installed or used in a non-English language environment.

Epson currently lists affected products across a number of printer families:

Product Category
Details
Inkjet Printers
Artisan, B Series, ColorWorks CW-C6xx, ET, PictureMate, Stylus C, Stylus CX, Stylus NX, Stylus Pro, WorkForce, XP
Photo Printers
Stylus Photo, Stylus Photo R, Stylus Pro
Large-Format Printers
Stylus Pro, SureColor, ML / Monna Lisa
Mini Lab Printers
SureLab D Series
Other
Epson Universal Printer Driver

Because Epson maintains the authoritative list of affected products, administrators should check the current Epson security advisory and the support page for their specific printer model rather than relying on a static model list.

How Does the Epson Printer Driver Vulnerability Work?

The vulnerability relates to the permissions applied by affected Epson Windows printer drivers in certain language environments.

According to JVN/JPCERT, the documented attack scenario assumes that a user is induced to place a specially crafted DLL file in a location selected by the attacker. The vulnerability can then potentially be exploited to execute arbitrary code with SYSTEM privileges.

That distinction is important.

CVE-2025-42598 should not be interpreted as meaning that an attacker can remotely compromise any Epson printer or that simply installing an Epson driver automatically compromises a Windows computer.

However, SYSTEM-level privileges are highly privileged within Windows, making remediation important wherever affected drivers remain installed.

How to Fix CVE-2025-42598

Epson has released a security countermeasure for the vulnerability.

IT administrators should take the following steps:

  1. Identify Windows systems using Epson printer drivers. Pay particular attention to systems where Windows or the Epson driver is being used in a language other than English.
  2. Run Epson Software Updater. Epson recommends using its updater to obtain the relevant security software.
  3. Install the Epson Printer Driver Security Support Tool. Epson currently distributes the tool through its Software Updater and individual product-support pages.
  4. Use the product support page if Software Updater is unavailable. Locate the affected printer on Epson's support site and download the latest available Epson Printer Driver Security Support Tool or security patch for that product.
  5. Verify deployment. In managed environments, confirm that remediation has been applied to all affected endpoints rather than relying on individual users to perform the update.

Epson currently provides version 1.0.1.0 of the Epson Printer Driver Security Support Tool on many product-support pages. However, administrators should always install the latest version offered by Epson for the relevant product rather than relying on a version number published in a third-party article.

How to Check Your Environment

For organizations managing multiple Windows endpoints and printers, a structured review can make remediation easier:

Inventory Epson printer drivers → identify affected Windows/language environments → deploy Epson's security tool → verify deployment → monitor Epson security advisories

Start by identifying endpoints on which Epson manufacturer drivers are installed. From there, determine whether those systems meet the conditions described in Epson's advisory and ensure the vendor's remediation has been deployed.

Epson currently reports that it has received no reports of attacks exploiting CVE-2025-42598, but that does not remove the need to patch affected systems.

How to Reduce Printer-Driver Risk Long Term

Applying Epson's security update is the correct way to address CVE-2025-42598 itself.

But the vulnerability also highlights a broader challenge for IT teams: traditional printing often requires manufacturer-specific drivers to be installed, maintained and updated across large numbers of endpoints.

Every additional driver package introduces another software component that IT must inventory, test, update and secure.

Cloud-based print management can reduce that dependency.

With ezeep, printer-specific rendering takes place in the cloud. End-user devices do not need the manufacturer's printer driver installed locally. Instead, users print through ezeep and the job is rendered for the destination printer in the cloud.

This architecture can help organizations:

  • reduce the number of manufacturer printer drivers deployed to endpoints,
  • centralize printer and print-policy management,
  • reduce ongoing driver administration,
  • support Windows, macOS, ChromeOS and mobile devices from one print environment,
  • and reduce endpoint exposure to vulnerabilities in locally installed manufacturer printer drivers.

Moving driver management away from endpoints does not replace the need to patch existing vulnerable systems. It can, however, reduce the number of endpoints on which vendor-specific printer software needs to be maintained in the future.

If you want to learn more about how ezeep makes your printing secure, visit the Security and Compliance page. If you are wanting more reading about Epson security, read the Seiko-Epson Printer Security Flaw blog post.

ezeep-for-WPP
Drop the Drivers
Print through the cloud.
Start Free Trial

Frequently Asked Questions

Is CVE-2025-42598 still relevant?

Yes, for systems on which affected Epson Windows printer drivers have not yet been remediated. Epson continues to publish its security advisory and remediation instructions for CVE-2025-42598. As of September 22, 2026, Epson states that it has received no reports of attacks exploiting the vulnerability.

Which Epson printer drivers are affected by CVE-2025-42598?

Epson and JVN/JPCERT state that a wide range of Epson printer drivers for Windows are affected when installed or used in a language other than English. Epson lists product families including WorkForce, ET, XP, SureColor, Stylus and the Epson Universal Printer Driver. Check Epson's current advisory for information about specific products.

What can an attacker do with CVE-2025-42598?

Successful exploitation may allow an attacker to execute arbitrary code with SYSTEM privileges on an affected Windows computer. JVN/JPCERT describes an attack scenario in which a user is induced to place a specially crafted DLL file in a location chosen by an attacker.

Is CVE-2025-42598 remotely exploitable?

The published CVSS assessment classifies the vulnerability's attack vector as local, rather than network-based. The documented attack scenario also requires user interaction.

How do I fix CVE-2025-42598?

Epson recommends running Epson Software Updater and installing the Epson Printer Driver Security Support Tool. If Software Updater is unavailable, the tool can be downloaded from the appropriate Epson product-support page.

Back to top