{
    "dataType": "CVE_RECORD",
    "dataVersion": "5.1",
    "cveMetadata": {
        "cveId": "CVE-2025-49797",
        "assignerOrgId": "ede6fdc4-6654-4307-a26d-3331c018e2ce",
        "state": "PUBLISHED",
        "assignerShortName": "jpcert",
        "dateReserved": "2025-06-11T04:48:58.284Z",
        "datePublished": "2025-06-25T09:25:53.381Z",
        "dateUpdated": "2025-08-19T06:48:21.242Z"
    },
    "containers": {
        "cna": {
            "affected": [
                {
                    "vendor": "BROTHER INDUSTRIES, LTD.",
                    "product": "Multiple driver installers for Windows",
                    "versions": [
                        {
                            "version": "see the information provided by the vendor",
                            "status": "affected"
                        }
                    ]
                },
                {
                    "vendor": "Toshiba Tec Corporation",
                    "product": "Multiple driver installers for Windows",
                    "versions": [
                        {
                            "version": "see the information provided by the vendor",
                            "status": "affected"
                        }
                    ]
                },
                {
                    "vendor": "Ricoh Company, Ltd.",
                    "product": "Multiple driver installers for Windows",
                    "versions": [
                        {
                            "version": "see the information provided by the vendor",
                            "status": "affected"
                        }
                    ]
                }
            ],
            "descriptions": [
                {
                    "lang": "en",
                    "value": "Multiple Brother driver installers for Windows contain a privilege escalation vulnerability. If exploited, an arbitrary program may be executed with the administrative privilege. As for the details of affected product names, model numbers, and versions, refer to the information provided by the respective vendors listed under [References]."
                }
            ],
            "problemTypes": [
                {
                    "descriptions": [
                        {
                            "description": "Files or directories accessible to external parties",
                            "lang": "en-US",
                            "cweId": "CWE-552",
                            "type": "CWE"
                        }
                    ]
                }
            ],
            "references": [
                {
                    "url": "https://support.brother.com/g/s/security/"
                },
                {
                    "url": "https://www.toshibatec.com/information/20250625_01.html"
                },
                {
                    "url": "https://www.ricoh.com/products/security/vulnerabilities/vul?id=ricoh-2025-000009"
                },
                {
                    "url": "https://jvn.jp/en/vu/JVNVU91819309/"
                }
            ],
            "metrics": [
                {
                    "format": "CVSS",
                    "scenarios": [
                        {
                            "lang": "en-US",
                            "value": "GENERAL"
                        }
                    ],
                    "cvssV3_0": {
                        "version": "3.0",
                        "baseSeverity": "HIGH",
                        "baseScore": 7.8,
                        "vectorString": "CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H"
                    }
                },
                {
                    "format": "CVSS",
                    "scenarios": [
                        {
                            "lang": "en-US",
                            "value": "GENERAL"
                        }
                    ],
                    "cvssV4_0": {
                        "version": "4.0",
                        "baseSeverity": "HIGH",
                        "baseScore": 8.5,
                        "vectorString": "CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N"
                    }
                }
            ],
            "providerMetadata": {
                "orgId": "ede6fdc4-6654-4307-a26d-3331c018e2ce",
                "shortName": "jpcert",
                "dateUpdated": "2025-08-19T06:48:21.242Z"
            }
        },
        "adp": [
            {
                "metrics": [
                    {
                        "other": {
                            "type": "ssvc",
                            "content": {
                                "timestamp": "2025-06-25T12:22:16.386782Z",
                                "id": "CVE-2025-49797",
                                "options": [
                                    {
                                        "Exploitation": "none"
                                    },
                                    {
                                        "Automatable": "no"
                                    },
                                    {
                                        "Technical Impact": "total"
                                    }
                                ],
                                "role": "CISA Coordinator",
                                "version": "2.0.3"
                            }
                        }
                    }
                ],
                "title": "CISA ADP Vulnrichment",
                "providerMetadata": {
                    "orgId": "134c704f-9b21-4f2e-91b3-4a467353bcc0",
                    "shortName": "CISA-ADP",
                    "dateUpdated": "2025-06-25T12:41:07.779Z"
                }
            }
        ]
    }
}