ZDI-23-670: (Pwn2Own) Lexmark MC3224i lbtraceapp Uncontrolled Search Path Element Local Privilege Escalation Vulnerability
This vulnerability allows local attackers to escalate privileges on affected installations of Lexmark MC3224i printers. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-23-670?
The ZDI-23-670 vulnerability has a high severity rating due to its potential for local privilege escalation.
How do I fix ZDI-23-670?
To fix ZDI-23-670, update the firmware of the Lexmark MC3224i printers to the latest version provided by the manufacturer.
Who is affected by ZDI-23-670?
ZDI-23-670 affects installations of Lexmark MC3224i printers that allow execution of low-privileged code.
Can remote attackers exploit ZDI-23-670?
No, ZDI-23-670 requires local access to the affected Lexmark MC3224i printer to exploit.
What action should be taken if ZDI-23-670 is discovered in my system?
If ZDI-23-670 is discovered, immediate steps to update firmware should be taken to mitigate the risk of privilege escalation.