Lexmark´òÓ¡»úí§Òâ´úÂëÖ´ÐÐ0dayÎó²î

Ðû²¼Ê±¼ä 2021-06-23

0x00 Îó²î¸ÅÊö

CVE    ID


ʱ      ¼ä

2021-06-23

Àà      ÐÍ

ÍâµØ´úÂëÖ´ÐÐ

µÈ      ¼¶

¸ßΣ

Ô¶³ÌʹÓÃ

·ñ

Ó°Ïì¹æÄ£


¹¥»÷ÖØÆ¯ºó

µÍ

¿ÉÓÃÐÔ

¸ß

Óû§½»»¥

ÎÞ

ËùÐèȨÏÞ

ÎÞ

PoC/EXP

δ¹ûÕæ

ÔÚҰʹÓÃ

·ñ

 

0x01 Îó²îÏêÇé

image.png

Lexmark£¨ÀûÃË£©ÊÇÒ»¼ÒרעÓÚ´òÓ¡ºÍÓ°Ïñ½â¾ö¼Æ»®µÄÑз¢ÉÌ¡¢Éú²úÉ̼°¹©Ó¦ÉÌ£¬£¬£¬Æä¿Í»§°üÀ¨ÁãÊÛ¡¢½ðÈÚЧÀÍ¡¢Ò½ÁƱ£½¡¡¢ÖÆÔì¡¢½ÌÓýºÍÕþ¸®µÈ£¬£¬£¬Æä´òÓ¡»úÔÚÈ«Çò¹æÄ£ÄÚ±»ÆÕ±éʹÓᣡ£¡£¡£¡£¡£

2021Äê06ÔÂ21ÈÕ£¬£¬£¬ÍâÑóÇå¾²Ñо¿Ô±ÔÚLexmark´òÓ¡»úÈí¼þG2×°ÖðüÖз¢Ã÷ÁËÒ»¸öí§Òâ´úÂëÖ´ÐÐ0dayÎó²î£¬£¬£¬ÆäCVSSv3»ù±¾ÆÀ·ÖΪ8.4¡£¡£¡£¡£¡£¡£

ÖÎÀíÔ±¿É×Ô½ç˵G2×°ÖðüµÄ×°Ö÷¾¶£¬£¬£¬LM__bdsvc.exeÊÇ´òÓ¡»úͨѶϵͳµÄÒ»²¿·Ö¡£¡£¡£¡£¡£¡£ÓÉÓÚLM__bdsvc Öб£´æÒ»¸öδ¼ÓÒýºÅµÄЧÀÍ·¾¶Îó²î£¬£¬£¬¹¥»÷Õß¿ÉÒÔͨ¹ý½«Ò»¸ö¿ÉÖ´ÐÐÎļþ²åÈëЧÀÍ·¾¶À´Ê¹ÓôËÎó²î£¬£¬£¬µ±Ð§ÀÍ»òÏµÍ³ÖØÐÂÆô¶¯Ê±£¬£¬£¬½«ÌáÉý¿ÉÖ´ÐÐÎļþµÄȨÏÞ¡£¡£¡£¡£¡£¡£¸ÃÎó²îÎÞÐèÌØÊâȨÏÞºÍÓû§½»»¥¼´¿ÉÍâµØÊ¹Ó㬣¬£¬ÇÒʹÓÃÖØÆ¯ºóµÍ¡£¡£¡£¡£¡£¡£

 

0x02 ´¦Öóͷ£½¨Òé

ÏÖÔÚ£¬£¬£¬¸ÃÎó²îÒÑÔÚIBM X-Force£¨»ùÓÚÔÆµÄÍþвÇ鱨¹²ÏíÆ½Ì¨£©¹ûÕæÅû¶£¬£¬£¬µ«LexmarkÔÝδÐÞ¸´¸ÃÎó²î£¬£¬£¬ÇÒÔÝδÐû²¼Ïà¹ØÇ徲ͨ¸æ¡£¡£¡£¡£¡£¡£

¹Ù·½Á´½Ó£º

https://www.lexmark.com/en_us/solutions/security/lexmark-security-advisories.html

 

0x03 ²Î¿¼Á´½Ó

https://exchange.xforce.ibmcloud.com/vulnerabilities/204093

https://www.lexmark.com/en_us/solutions/security/lexmark-security-advisories.html

https://threatpost.com/lexmark-printers-code-execution-zero-day/167111/

 

0x04 ʱ¼äÏß

2021-06-21  IBM X-Force¹ûÕæÅû¶

2021-06-23  VSRCÐû²¼Ç徲ͨ¸æ

 

0x05 ¸½Â¼

CVSSÆÀ·Ö±ê×¼¹ÙÍø£ºhttp://www.first.org/cvss/

image.png