ZDI-CAN-19858: ZDI-23-670: (Pwn2Own) Lexmark MC3224i lbtraceapp Uncontrolled Search Path Element Local Privilege Escalation Vulnerability
Published May 17, 2023
·Updated
This vulnerability allows local attackers to escalate privileges on affected installations of Lexmark MC3224i printers. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability.
Affected Software
1 affected component
Lexmark MC3224i
Event History
May 17, 2023
Advisory Published
05:00 AM
Data Sourced
05:00 AM
Description
Frequently Asked Questions
1
What is the severity of ZDI-CAN-19858?
ZDI-CAN-19858 is classified as a privilege escalation vulnerability.
2
How do I fix ZDI-CAN-19858?
To mitigate ZDI-CAN-19858, update the firmware of your Lexmark MC3224i printer to the latest version provided by the manufacturer.
3
Who is affected by ZDI-CAN-19858?
ZDI-CAN-19858 affects Lexmark MC3224i printers with vulnerable firmware.
4
What type of attack is described in ZDI-CAN-19858?
ZDI-CAN-19858 describes a local privilege escalation attack.
5
What must an attacker do to exploit ZDI-CAN-19858?
An attacker must first have the ability to execute low-privileged code on the Lexmark MC3224i printer.