Impact
The vulnerability results from an unquoted Windows service executable path in Canon IJ Scan Utility. This flaw allows a local attacker to run an arbitrary file with the privileges of the affected service, potentially enabling the attacker to elevate privileges or maintain persistence on the system. The likely attack vector is a local execution that exploits the unquoted path; remote exploitation has not been documented.
Affected Systems
Canon Inc. provides the affected product, IJ Scan Utility for Windows, with vulnerable releases from version 1.1.2 through 1.5.0. Versions newer than 1.5.0 are not affected by this issue.
Risk and Exploitability
The CVSS score of 8.4 indicates high severity. The EPSS score of <1% implies a low probability of exploitation at the time of analysis, and the vulnerability is not listed in the CISA KEV catalog. Nonetheless, because the flaw permits execution with elevated service privileges, it should be remediated promptly. The problem is local and requires an attacker to have access to the target machine to trigger.
OpenCVE Enrichment