2025: Security Advisory: Canon UFR Driver Vulnerability
Summary | As stated on the Canon website, It has been found that the Canon Printer Drivers before version 3.15 have a buffer overflow vulnerability. These Canon Drivers can optionally be distributed as part of the SmartClient Installer Packages within uniFLOW Online. |
Advisory release date | Mar 28, 2025 |
Product | uniFLOW Online |
CVE | CVE-2025-1268 |
Summary of Vulnerability
Out-of-bounds vulnerability was found in certain printer drivers for production printers, office/small office multifunction printers and laser printers that may prevent printing and/or potentially be able to execute arbitrary code when the print is processed by a malicious application.
For further information please also see: CP2025-003 Vulnerability Remediation for Certain Printer Drivers for Production Printers, Office/Small Office Multifunction Printers and Laser Printers - Canon PSIRT
Severity
CVSS v3 CVSS: 3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L Base Score: 9.4
Affected Versions
Product | Affected versions |
uniFLOW Online |
|
Fixed Versions
Product | Fix versions |
uniFLOW Online |
|
What You Need to Do
To check if you are impacted by this vulnerability please follow the below procedure.
Browse to your uniFLOW Online tenant’s web interface
Login in with a user that has Administrator rights.
Click the profile icon in the top right of the screen, next to your display name
Selected Advanced for Administrator view, Click Save
Browse to Extensions > uniFLOW SmartClient > Installer configuration and creation > Manage Installers
Select each SmartClient Package (ignoring the Mac SmartClient Packages).
Check if any of the following are set
Printer Driver: Canon Generic Plus UFR II Printer Driver
Printer Driver: Canon Generic Plus GPLX Printer Driver
Canon PDF Driver: Enable Canon PDF Driver = Checked
If a, b or c are true, then you will need to follow the steps in the Mitigation section.
If a, b and c are false, then you do not need to do anything.
Mitigation
uniFLOW Online 2025.1.2 (3rd April) is updated with the latest drivers from Canon (that are not subject to the vulnerability).
Browse to Extensions > uniFLOW SmartClient > Installer configuration and creation > Manage Installers
for the lines that have the ‘Update Available’ status
select and double click the line to open the settings tabs
select the ‘Configure Installer’ tab
Click the 'Update Installer' button
The Updating uniFLOW SmartClient Installer dialogue is displayed.
Click the 'update now'
when it is finished re-creating the installer, select the 'Installer versions' tab.
select the latest one at the top of the list
select the … button to the right of the row.
either
'Publish' the new installer
if you use automatic updates, the driver will be updated on the client PC’s automatically
or if this package is ‘Shown on the Start printing page’, users can download the updated SmartClient Installer Package from the uniFLOW Online Start Printing Page
‘Download’ the new installer and roll out via your preferred software distribution method.
Support
If you have further questions, please contact your Canon / Canon Business Partner representative.