ZDI-23-667: (Pwn2Own) Lexmark MC3224i lbtraceapp _WriteTarFile Command Injection Privilege Escalation Vulnerability
This vulnerability allows local attackers to escalate privileges on affected installations of Lexmark MC3224i printers. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-23-667?
The ZDI-23-667 vulnerability has a high severity rating due to its potential to allow local privilege escalation on Lexmark MC3224i printers.
How do I fix ZDI-23-667?
To address the ZDI-23-667 vulnerability, ensure that you apply the latest firmware updates provided by Lexmark for the MC3224i printers.
Who is affected by ZDI-23-667?
The ZDI-23-667 vulnerability affects users of Lexmark MC3224i printers that have not been patched against this privilege escalation issue.
What type of attack does ZDI-23-667 enable?
ZDI-23-667 enables local attackers to escalate their privileges after executing low-privileged code on the affected Lexmark MC3224i printers.
What environments are at risk for ZDI-23-667?
Environments utilizing Lexmark MC3224i printers that allow access to low-privileged code execution are at risk for the ZDI-23-667 vulnerability.