Lucene search

K
zdiChristopher Anastasio @mufinnnnnnn and Justin Taft @JustTaftZDI-22-382
HistoryFeb 18, 2022 - 12:00 a.m.

Lexmark MC3224i PostScript Out-Of-Bounds Write Remote Code Execution Vulnerability

2022-02-1800:00:00
Christopher Anastasio @mufinnnnnnn and Justin Taft @JustTaft
www.zerodayinitiative.com
11

0.044 Low

EPSS

Percentile

92.4%

This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Lexmark MC3224i printers. Authentication is not required to exploit this vulnerability. The specific flaw exists within the parsing of PostScript data. Crafted PostScript data can trigger a write past the end of an allocated buffer. An attacker can leverage this vulnerability to execute code in the context of root.

0.044 Low

EPSS

Percentile

92.4%