Lucene search

K
zdiNxhoang99, HaToan, QuangHV99 from VcsLab of Viettel Cyber SecurityZDI-23-1174
HistoryAug 24, 2023 - 12:00 a.m.

(Pwn2Own) HP Color LaserJet Pro M479fdw msws Server-Side Request Forgery Remote Code Execution Vulnerability

2023-08-2400:00:00
nxhoang99, HaToan, QuangHV99 from VcsLab of Viettel Cyber Security
www.zerodayinitiative.com
5
pwn2own
network-adjacent
remote code execution
hp color laserjet pro
m479fdw
authentication
msws service
uri validation
udwserv service

0.004 Low

EPSS

Percentile

74.6%

This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of HP Color LaserJet Pro M479fdw printer. Authentication is not required to exploit this vulnerability. The specific flaw exists within the msws service. The issue results from the lack of proper validation of a URI prior to accessing resources. An attacker can leverage this vulnerability to execute code in the context of udwserv service.

0.004 Low

EPSS

Percentile

74.6%

Related for ZDI-23-1174