ZDI-24-082: (Pwn2Own) Lexmark CX331adwe PDF File Parsing Memory Corruption Remote Code Execution Vulnerability
Published Jan 31, 2024
·Updated
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Lexmark CX331adwe printers. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.5. The following CVEs are assigned: CVE-2023-50735.
Affected Software
1 affected component
Lexmark CX331adwe printer
Event History
Jan 31, 2024
Advisory Published
via ZDI·06:00 AM
Data Sourced
via ZDI·06:00 AM
Description
Frequently Asked Questions
1
What is the severity of ZDI-24-082?
The severity of ZDI-24-082 is rated at 7.5 on the CVSS scale.
2
How do I fix ZDI-24-082?
To fix ZDI-24-082, update your Lexmark CX331adwe printer firmware to the latest version provided by Lexmark.
3
What types of attacks can exploit ZDI-24-082?
ZDI-24-082 allows remote attackers to execute arbitrary code on affected Lexmark CX331adwe printers.
4
Do I need authentication to exploit ZDI-24-082?
No, authentication is not required to exploit ZDI-24-082.
5
Which devices are affected by ZDI-24-082?
The only affected device identified for ZDI-24-082 is the Lexmark CX331adwe printer.