CVE-2025-14237

9.8

Canon · Satera, imageCLASS, i-SENSYS, and imageRUNNER Series Printers

A buffer overflow vulnerability in the XPS font parsing process of multiple Canon printer series allows unauthenticated network attackers to trigger system crashes or execute arbitrary code.

Executive summary

A critical out-of-bounds write vulnerability in Canon printer firmware poses a severe risk of remote code execution or denial of service for affected network-connected devices.

Vulnerability

This vulnerability is an out-of-bounds write flaw (CWE-787) triggered during the processing of XPS font data. The vulnerability is accessible to unauthenticated attackers residing on the same network segment as the printer.

Business impact

The CVSS score of 9.8 reflects the high potential for impact, as the vulnerability allows unauthenticated remote code execution. Successful exploitation could lead to full loss of system integrity and availability, potentially allowing attackers to pivot into the internal network from the printer, intercept sensitive documents, or render critical office printing infrastructure completely unresponsive.

Remediation

Immediate Action: Update all affected Canon printer firmware to the version provided in the official vendor advisory (v06.03 or later).

Proactive Monitoring: Monitor network traffic for unusual activity originating from or directed toward printer management interfaces, particularly traffic utilizing the XPS print protocol.

Compensating Controls: Isolate printers on a restricted management VLAN with strict access control lists to ensure they are not reachable from untrusted network segments.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

Given the critical severity and the nature of the flaw, administrators should prioritize the firmware update across their printer fleet immediately. Devices that cannot be updated should be removed from internet-facing or insecure network segments to prevent unauthorized remote exploitation.

More Canon CVEs

History

  1. Disclosed CVE record published
  2. Published in the daily brief critical section
  3. Published in the daily brief critical section
  4. Analyst report written

Sources