ZDI-25-221: (Pwn2Own) Lexmark CX331adwe httpd extract-trace Link Following Local Privilege Escalation Vulnerability
This vulnerability allows local attackers to escalate privileges on affected installations of Lexmark CX331adwe printers. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.0.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-25-221?
The severity of ZDI-25-221 is determined by its ability to allow local privilege escalation on affected Lexmark CX331adwe printers.
How do I fix ZDI-25-221?
To fix ZDI-25-221, apply the latest firmware updates provided by Lexmark for the CX331adwe printer.
Who is affected by ZDI-25-221?
Local attackers with low-privileged access to Lexmark CX331adwe printers are affected by ZDI-25-221.
What type of attack does ZDI-25-221 enable?
ZDI-25-221 enables local privilege escalation attacks on affected Lexmark CX331adwe printers.
What must an attacker do to exploit ZDI-25-221?
An attacker must first execute low-privileged code on the target Lexmark CX331adwe printer system to exploit ZDI-25-221.