CVE-2026-1585
Received
Received - Intake
Unquoted Service Path Vulnerability in IJ Scan Utility Enables Privilege Escalation
Publication date: 2026-02-27
Last updated on: 2026-03-03
Assigner: Canon Inc.
Description
Description
An unquoted Windows service executable path vulnerability in IJ Scan Utility for Windows versions 1.1.2 through 1.5.0 may allow a local attacker to execute a malicious file with the privileges of the affected service.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| canon | ij_scan_utility | From 1.1.2 (inc) to 1.5.0 (inc) |
| canon | ij_scan_utility_for_windows | From 1.1.2 (inc) to 1.5.0 (inc) |
| canon | ij_scan_utility_for_windows | 1.6.0 |
| canon | ij_scan_utility | 1.6.0 |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-428 | The product uses a search path that contains an unquoted element, in which the element contains whitespace or other separators. This can cause the product to access resources in a parent path. |