ZDI-CAN-28477: ZDI-26-062: (Pwn2Own) Lexmark CX532adwe esfhelper Untrusted Search Path Local Privilege Escalation Vulnerability
This vulnerability allows local attackers to escalate privileges on affected installations of Lexmark CX532adwe printers. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2025-65078.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-CAN-28477?
ZDI-CAN-28477 is classified as a local privilege escalation vulnerability that poses a moderate risk to affected systems.
How do I fix ZDI-CAN-28477?
To remediate ZDI-CAN-28477, ensure that proper security configurations are applied and restrict unauthorized access to the device.
Who is affected by ZDI-CAN-28477?
ZDI-CAN-28477 affects installations of the Lexmark CX532adwe printer that allow local attackers the ability to execute low-privileged code.
What could an attacker do with ZDI-CAN-28477?
An attacker leveraging ZDI-CAN-28477 could escalate their privileges to gain higher access on the affected Lexmark printer.
When was ZDI-CAN-28477 disclosed?
ZDI-CAN-28477 was disclosed in the context of the Pwn2Own event, highlighting its significance in the cybersecurity community.