ZDI-25-074: (Pwn2Own) Canon imageCLASS MF656Cdw TIF File Parsing Stack-based Buffer Overflow Remote Code Execution Vulnerability
This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Canon imageCLASS MF656Cdw printers. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 8.8. The following CVEs are assigned: CVE-2024-12648.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-25-074?
The severity of ZDI-25-074 is rated at 8.8, indicating a high level of risk.
How do I fix ZDI-25-074?
To fix ZDI-25-074, update the firmware of the Canon imageCLASS MF656Cdw printer to the latest version provided by Canon.
Who is affected by ZDI-25-074?
ZDI-25-074 affects installations of Canon imageCLASS MF656Cdw printers without requiring authentication for exploitation.
What type of attack does ZDI-25-074 allow?
ZDI-25-074 allows network-adjacent attackers to execute arbitrary code on vulnerable printers.
Is authentication needed to exploit ZDI-25-074?
No, authentication is not required to exploit ZDI-25-074.