ZDI-CAN-19766: ZDI-23-667: (Pwn2Own) Lexmark MC3224i lbtraceapp _WriteTarFile Command Injection Privilege Escalation Vulnerability
This vulnerability allows local attackers to escalate privileges on affected installations of Lexmark MC3224i printers. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-CAN-19766?
ZDI-CAN-19766 has a high severity due to its potential for local privilege escalation on Lexmark MC3224i printers.
How do I fix ZDI-CAN-19766?
To fix ZDI-CAN-19766, apply the latest firmware updates provided by Lexmark for the MC3224i printer.
What are the risks associated with ZDI-CAN-19766?
The risks associated with ZDI-CAN-19766 include unauthorized access and modification of printer settings by local attackers.
Who is affected by ZDI-CAN-19766?
Organizations using Lexmark MC3224i printers with vulnerable firmware are affected by ZDI-CAN-19766.
Can ZDI-CAN-19766 be exploited remotely?
No, ZDI-CAN-19766 requires local access to the affected printer to exploit the vulnerability.