First published: Mon Jul 19 2021(Updated: )
The Lexmark Universal Print Driver version 2.15.1.0 and below, G2 driver 2.7.1.0 and below, G3 driver 3.2.0.0 and below, and G4 driver 4.2.1.0 and below are affected by a privilege escalation vulnerability. A standard low priviliged user can use the driver to execute a DLL of their choosing during the add printer process, resulting in escalation of privileges to SYSTEM.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Lexmark G2 Driver | <=2.7.1.0 | |
Lexmark G3 Driver | <=3.2.0.0 | |
Lexmark G4 Driver | <=4.2.1.0 | |
Lexmark Universal Print Driver | <=2.15.1.0 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-35449 is a privilege escalation vulnerability affecting the Lexmark Universal Print Driver version 2.15.1.0 and below, G2 driver 2.7.1.0 and below, G3 driver 3.2.0.0 and below, and G4 driver 4.2.1.0 and below.
It allows a standard low privileged user to execute a DLL of their choosing during the driver setup wizard.
CVE-2021-35449 has a severity rating of 7.8 (high).
CVE-2021-35449 affects Lexmark Universal Print Driver version 2.15.1.0 and below, G2 driver 2.7.1.0 and below, G3 driver 3.2.0.0 and below, and G4 driver 4.2.1.0 and below.
At the time of writing this FAQ, there is no specific fix or patch available for CVE-2021-35449. It is recommended to follow the recommendations provided by Lexmark and stay updated on any official advisories or patches.