ZDI-22-329: (Pwn2Own) Lexmark MC3224i setuid Local Privilege Escalation Vulnerability
This vulnerability allows local attackers to escalate privileges on affected installations of Lexmark MC3224i printers. An attacker must first obtain the ability to execute low-privileged code on the target guest system in order to exploit this vulnerability. The specific flaw exists within the permissions set on root-owned service files. An attacker can leverage this vulnerability to escalate privileges and execute arbitrary code in the context of root.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-22-329?
The severity of ZDI-22-329 is classified as a high privilege escalation vulnerability.
How do I fix ZDI-22-329?
To mitigate ZDI-22-329, ensure that Lexmark MC3224i printers are updated to the latest firmware version.
What types of attacks are possible with ZDI-22-329?
ZDI-22-329 allows local attackers to escalate privileges after executing low-privileged code.
Which devices are affected by ZDI-22-329?
The vulnerability ZDI-22-329 specifically affects Lexmark MC3224i printers.
Is exploitation of ZDI-22-329 remote or local?
Exploitation of ZDI-22-329 requires local access to the affected system.