CVE-2025-4960

7.8

Epson · Printer Controller Installer

A local privilege escalation vulnerability in the Epson Printer Controller Installer allows unprivileged users to execute arbitrary commands with elevated system privileges via the XPC protocol.

Executive summary

A critical local privilege escalation flaw in the Epson Printer Controller Installer enables unprivileged users to gain full system control.

Vulnerability

The com.epson.InstallNavi.helper tool fails to enforce proper authentication over XPC and uses overly permissive custom rights in the macOS authorization database. Any local user can exploit this to perform privileged operations without administrative credentials.

Business impact

This vulnerability poses a significant risk to organizational endpoints by allowing local attackers to bypass security boundaries, potentially leading to full system compromise. With a CVSS score of 7.8, this high-severity flaw enables unauthorized software installation, data exfiltration, or persistence mechanisms, severely impacting the integrity and confidentiality of affected macOS systems.

Remediation

Immediate Action: Since a specific patch version is currently unknown, administrators should identify and remove the vulnerable EPSON Printer Controller Installer helper tool from all affected macOS endpoints.

Proactive Monitoring: Monitor system logs for unauthorized XPC communication attempts or unexpected modifications to the /var/db/auth.db file.

Compensating Controls: Restrict local user permissions where possible and utilize endpoint detection and response (EDR) solutions to flag suspicious child processes originating from the InstallNavi helper.

Exploitation status

Public Exploit Available: Yes — as documented in the research write-up referenced by the CVE record.

Analyst recommendation

Given the capability for local privilege escalation and the availability of proof-of-concept details, this vulnerability presents an urgent risk to macOS environments. Organizations should prioritize the identification of this software in their inventory and remove the vulnerable component until a vendor-supplied security update is confirmed and deployed.

More Epson CVEs

Sources

Originally found and disclosed by Carlos Garrido of Pentraze Cybersecurity, per the CVE Program record.