Home Canon CVE-2025-14237
Back to Canon

CVE-2025-14237

Canon Laser Printers and Small Office Multifunctional Printers - XPS Font Parse Processing

Canon CVSS 9.8 Updated April 6, 2026

Executive Risk Summary

"A buffer overflow vulnerability in the XPS font parse processing of Canon Laser Printers and Small Office Multifunctional Printers may allow an attacker on the network segment to trigger the affected product being unresponsive or to execute arbitrary code. This vulnerability affects various Canon printer models sold in Japan, the US, and Europe with firmware version v06.02 and earlier."

Anticipated Attack Path

  1. 1. Attacker sends a maliciously crafted XPS font file to the printer
  2. 2. The printer's XPS font parse processing component attempts to process the file, triggering the buffer overflow
  3. 3. The buffer overflow allows the attacker to execute arbitrary code on the printer

Am I Vulnerable?

  • Verify the firmware version of the Canon printer
  • Check for any suspicious network activity targeting the printer
  • Apply the firmware update provided by Canon to remediate the vulnerability

Operational Audit Arsenal

Target Type Firmware
Target Asset XPS Font Parse Processing
Standard Path Canon Laser Printers and Small Office Multifunctional Printers

Manual Verification Required

This is a non-Windows asset (Canon). Use the target asset details and official path provided above to verify your current version against the official vendor advisories listed below.

Patch Impact Forecast

Reboot Required Likely

Potential disruption to printing services during the firmware update process

Internal Work Notes

CVE-2025-14237: Buffer overflow vulnerability in Canon Laser Printers and Small Office Multifunctional Printers - XPS Font Parse Processing. Apply firmware update to remediate the vulnerability.

Technical Intelligence & Operational Utilities • Delivered Weekly

Intelligence Sources

Related Canon Threats

Data compiled from NVD, MSRC, and CISA KEV Catalog. Intelligence synthesized via AI. Scripts provided for diagnostic purposes under MIT License.