CVE-2021-44735: (Pwn2Own) Lexmark MC3224i setuid Local Privilege Escalation Vulnerability
Embedded web server command injection vulnerability in Lexmark devices through 2021-12-07.
Other sources
This vulnerability allows local attackers to escalate privileges on affected installations of Lexmark MC3224i printers. An attacker must first obtain the ability to execute low-privileged code on the target guest system in order to exploit this vulnerability. The specific flaw exists within the permissions set on root-owned service files. An attacker can leverage this vulnerability to escalate privileges and execute arbitrary code in the context of root.
This vulnerability allows local attackers to escalate privileges on affected installations of Lexmark MC3224i printers. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The specific flaw exists within the permissions set on root-owned service files. An attacker can leverage this vulnerability to escalate privileges and execute arbitrary code in the context of root.
This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Lexmark MC3224i printers. Although authentication is required to exploit this vulnerability, the existing authentication mechanism can be bypassed. The specific flaw exists within the processing of packet captures. When parsing the filter property, the process does not properly validate a user-supplied string before using it to execute a system call. An attacker can leverage this vulnerability to execute code in the context of the www-data user.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2021-44735?
The severity of CVE-2021-44735 is critical as it allows local attackers to escalate privileges on Lexmark MC3224i printers.
How do I fix CVE-2021-44735?
To fix CVE-2021-44735, you should apply the latest firmware updates provided by Lexmark for affected devices.
Which devices are affected by CVE-2021-44735?
CVE-2021-44735 specifically affects Lexmark MC3224i printers among other models.
What type of vulnerability is CVE-2021-44735?
CVE-2021-44735 is classified as a command injection vulnerability in the embedded web server of Lexmark devices.
Can CVE-2021-44735 be exploited remotely?
No, exploitation of CVE-2021-44735 requires local access to the affected Lexmark devices.