ZDI-23-552: (Pwn2Own) Canon imageCLASS MF743Cdw Authorization Stack-based Buffer Overflow Remote Code Execution Vulnerability
This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Canon imageCLASS MF743Cdw printers. Authentication is not required to exploit this vulnerability.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-23-552?
The ZDI-23-552 vulnerability is considered critical due to its potential for arbitrary code execution by unauthorized users.
How do I fix ZDI-23-552?
To mitigate ZDI-23-552, it is important to apply the official firmware updates provided by Canon for the imageCLASS MF743Cdw printer.
Can ZDI-23-552 be exploited remotely?
Yes, ZDI-23-552 can be exploited by network-adjacent attackers without the need for authentication.
What impact does ZDI-23-552 have on Canon imageCLASS MF743Cdw printers?
ZDI-23-552 allows attackers to execute arbitrary code on affected Canon imageCLASS MF743Cdw printers, compromising their security.
Is there a workaround for ZDI-23-552 before applying the fix?
Disabling remote access features on the Canon imageCLASS MF743Cdw can serve as a temporary workaround for ZDI-23-552.