Canon Printer Flaw Exposes Devices to Remote Code Execution

Canon Printer Drivers Found Vulnerable to Remote Code Execution

Canon has released an urgent security alert regarding a newly discovered vulnerability affecting multiple printer drivers, which could allow cybercriminals to execute arbitrary code on compromised systems.

High-Risk Security Threat Identified

The vulnerability, cataloged as CVE-2025-1268, has been assigned a high-severity CVSS score of 9.4, signifying serious security consequences for users of impacted Canon devices.

Nature of the Security Flaw

Cybersecurity analysts have pinpointed a critical out-of-bounds vulnerability within the EMF Recode processing feature of Canon’s Generic Plus printer drivers. Exploiting this flaw, malicious actors could execute unauthorized code when print jobs are processed via a compromised application.

Key aspects of the vulnerability include:

  • Severity: Critical (CVSS 9.4)
  • Impact: Remote code execution and potential operational disruption
  • Exploitation Complexity: Low, requiring no user interaction, elevated privileges, or special access conditions
  • Potential Threat: Could serve as an entry point for broader cyberattacks, compromising data security and system integrity

This flaw poses a major risk, as it allows attackers to exploit affected printers without requiring any direct interaction from users.

Acknowledgment & Discovery

Canon has credited the Microsoft Offensive Research and Security Engineering Team (MORSE) for responsibly disclosing this vulnerability, with special recognition given to researcher Robert Ord for identifying the issue.

Impacted Printer Drivers

The following Canon printer drivers are affected:

  • Generic Plus PCL6 Printer Driver (V3.12 and earlier)
  • Generic Plus UFR II Printer Driver (V3.12 and earlier)
  • Generic Plus LIPS4 Printer Driver (V3.12 and earlier)
  • Generic Plus LIPSLX Printer Driver (V3.12 and earlier)
  • Generic Plus PS Printer Driver (V3.12 and earlier)

These drivers are widely used across various Canon printer models, including office multifunction devices and production printers, potentially affecting thousands of businesses and users worldwide.

Urgent Security Measures

Canon strongly urges all users to immediately update their printer drivers to the latest versions available via their regional Canon support websites. Failing to do so could leave systems exposed to potential cyberattacks.

To further mitigate risks, IT teams are advised to:

  • Apply network segmentation to isolate print servers from critical infrastructure
  • Enable logging and monitoring for unusual printing activities
  • Restrict printer access to authorized users only

By taking these proactive steps, organizations can minimize exposure to this critical security vulnerability and safeguard their printing environments against exploitation.

More Articles & Posts