Lucene search

K
cvelistMitreCVELIST:CVE-2021-38085
HistoryAug 11, 2021 - 5:39 p.m.

CVE-2021-38085

2021-08-1117:39:38
mitre
www.cve.org
2

8.5 High

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

21.2%

The Canon TR150 print driver through 3.71.2.10 is vulnerable to a privilege escalation issue. During the add printer process, a local attacker can overwrite CNMurGE.dll and, if timed properly, the overwritten DLL will be loaded into a SYSTEM process resulting in escalation of privileges. This occurs because the driver drops a world-writable DLL into a CanonBJ %PROGRAMDATA% location that gets loaded by printisolationhost (a system process).

8.5 High

AI Score

Confidence

High

0.001 Low

EPSS

Percentile

21.2%