ZDI-CAN-22443: ZDI-24-082: (Pwn2Own) Lexmark CX331adwe PDF File Parsing Memory Corruption Remote Code Execution Vulnerability
Published Jan 31, 2024
·Updated
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Lexmark CX331adwe printers. Authentication is not required to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.5. The following CVEs are assigned: CVE-2023-50735.
Affected Software
1 affected component
Lexmark CX331adwe
Event History
Jan 31, 2024
Advisory Published
via ZDI·06:00 AM
Data Sourced
via ZDI·06:00 AM
Description
Frequently Asked Questions
1
What is the severity of ZDI-CAN-22443?
The severity of ZDI-CAN-22443 is rated at 7.5 on the CVSS scale.
2
What is the CVE associated with ZDI-CAN-22443?
The CVE associated with ZDI-CAN-22443 is CVE-2023-50735.
3
Who is affected by ZDI-CAN-22443?
ZDI-CAN-22443 affects Lexmark CX331adwe printers.
4
Is authentication required to exploit ZDI-CAN-22443?
No, authentication is not required to exploit ZDI-CAN-22443.
5
What can attackers do with ZDI-CAN-22443?
Attackers can execute arbitrary code on affected Lexmark CX331adwe printers due to ZDI-CAN-22443.