Epson Connect Security Hole

Issue abstract: Epson Connect signs off my user account, signs on a system account that I could not determine, does something, and then turns off the computer.

Detailed description: I recently installed an Epson XP7100 printer. As part of the installation it suggested installing Epson Connect to allow remote over the Internet sending of print jobs. After Epson Connect was set up, I would periodically find my computer was shutdown. Normally it runs 24/7. After several episodes I started investigating through the Windows logs and discovered that my user account would be logged out by some software. A system account would do a special login. The logs did not specify what the account was. After a few minutes the computer would shut down.

The only recent new software, and the fact that Epson Connect was attached to an Epson server made me suspicious that this was the problem. I shutdown Epson Connect and removed that software and the problem has not happened since.

Norton 360 did not catch what was going on.

Product & version number: Norton 360 latest verion

OS details: Windows 11 Professional

What is the error message you are seeing? See description

If you have any supporting screenshots, please add them:

Indeed, Epson Connect is a part of the issue you were seeing. Norton SHOULD have protected the OS, being that your software for Epson was being granted full admin access Norton trusted it. Is there anything in your Norton history that might help with determining things a bit clearer? Have you looked for hidden account on the computer as well?

AI Overview

To find hidden user accounts on Windows 11, open an

elevated Command Prompt (search for “cmd”, right-click, and select “Run as administrator”) and type the command net user to see a list of all accounts, including hidden and system accounts. You can also view accounts in the Settings app under Accounts > Other users or manage them in Computer Management > Local Users and Groups (if available in your edition).

I found vulnerabilities in the model of printer and its drivers you should review below:

*** Have you installed a non-English driver set?**

Formal Vulnerabilities listing:

SA

Thanks for the help.

I didn’t find any accounts that I didn’t expect.

I didn’t install any non-English drivers.

As it hasn’t happened further, I just wanted to let others know of the issue.

1 Like

Ok great!! Thanks for the post back. Hoping others also see there are software patches that should be installed as well as the listing of what those vulnerabilities are.

Regards,
SA