CVE-2025-57797

7.8

PFU Limited · ScanSnap Manager

An incorrect privilege assignment vulnerability in PFU Limited ScanSnap Manager installers allows authenticated local attackers to escalate privileges and execute arbitrary commands.

Executive summary

A critical local privilege escalation vulnerability in PFU Limited ScanSnap Manager allows authenticated attackers to gain elevated system permissions and execute arbitrary commands.

Vulnerability

The software contains an incorrect privilege assignment flaw (CWE-266) within its installer, which can be leveraged by an authenticated local attacker to achieve privilege escalation and arbitrary command execution.

Business impact

Successful exploitation of this vulnerability poses a severe risk to organizational security by allowing a local user to bypass security controls and gain full administrative control over the affected workstation. Given the CVSS score of 7.8, this vulnerability represents a high risk to data integrity and system availability, as an attacker with low-level access can escalate their privileges to perform unauthorized actions, install malicious software, or compromise sensitive documentation processed by the scanner.

Remediation

Immediate Action: Update ScanSnap Manager to version V6.5L61 or later immediately to resolve the privilege assignment flaw.

Proactive Monitoring: Audit system logs for unexpected process execution or privilege changes occurring after the installation of software packages.

Compensating Controls: Restrict local user access to installation directories and monitor local system accounts for unauthorized privilege changes until the update is deployed.

Exploitation status

Public Exploit Available: Unknown

Analyst recommendation

Organizations should prioritize the deployment of the V6.5L61 update across all systems running ScanSnap Manager to mitigate the risk of local privilege escalation. Ensuring that standard user accounts lack the ability to modify installer configurations or run elevated installation processes is a critical secondary defense against this class of vulnerability.

Sources