# CVE-2025-49797

## Summary

- **CVE ID:** CVE-2025-49797
- **Severity:** HIGH
- **CVSS Score:** 8.5 (CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N)
- **CWE:** CWE-552
- **Published:** Jun 25, 2025
- **Last Modified:** Mar 13, 2026

## Description

Multiple Brother driver installers for Windows contain a privilege escalation vulnerability. If exploited, an arbitrary program may be executed with the administrative privilege. As for the details of affected product names, model numbers, and versions, refer to the information provided by the respective vendors listed under [References].

## Affected Products

- BROTHER INDUSTRIES, LTD. — Multiple driver installers for Windows (see the information provided by the vendor)
- Toshiba Tec Corporation — Multiple driver installers for Windows (see the information provided by the vendor)
- Ricoh Company, Ltd. — Multiple driver installers for Windows (see the information provided by the vendor)

## References

- [CNA](https://support.brother.com/g/s/security/)
- [CNA](https://www.toshibatec.com/information/20250625_01.html)
- [CNA](https://www.ricoh.com/products/security/vulnerabilities/vul?id=ricoh-2025-000009)
- [CNA](https://jvn.jp/en/vu/JVNVU91819309/)

## Exploitation Prediction (EPSS)

- **EPSS Score:** 0.16%
- **EPSS Percentile:** 5.2

---
_Exported from OnDuty AI Vulnerability Intelligence on 2026-09-11._