ZDI-25-218: (Pwn2Own) Lexmark CX331adwe JPEG2000 Memory Corruption Remote Code Execution Vulnerability
This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Lexmark CX331adwe printers. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 8.8. The following CVEs are assigned: CVE-2024-11345.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-25-218?
The vulnerability ZDI-25-218 has been assigned a CVSS rating of 8.8, indicating high severity.
How can I fix ZDI-25-218?
To fix vulnerability ZDI-25-218, ensure that your Lexmark CX331adwe printers are updated with the latest firmware provided by Lexmark.
Who is affected by ZDI-25-218?
The vulnerability ZDI-25-218 affects installations of Lexmark CX331adwe printers.
Can ZDI-25-218 be exploited without authentication?
Yes, vulnerability ZDI-25-218 can be exploited by network-adjacent attackers without requiring authentication.
What type of attack is possible with ZDI-25-218?
Vulnerability ZDI-25-218 allows network-adjacent attackers to execute arbitrary code on vulnerable Lexmark printers.