Lexmark´òÓ¡»úí§Òâ´úÂëÖ´ÐÐ0dayÎó²î
Ðû²¼Ê±¼ä 2021-06-230x00 Îó²î¸ÅÊö
CVE ID | ʱ ¼ä | 2021-06-23 | |
Àà ÐÍ | ÍâµØ´úÂëÖ´ÐÐ | µÈ ¼¶ | ¸ßΣ |
Ô¶³ÌʹÓà | ·ñ | Ó°Ïì¹æÄ£ | |
¹¥»÷ÖØÆ¯ºó | µÍ | ¿ÉÓÃÐÔ | ¸ß |
Óû§½»»¥ | ÎÞ | ËùÐèȨÏÞ | ÎÞ |
PoC/EXP | δ¹ûÕæ | ÔÚҰʹÓà | ·ñ |
0x01 Îó²îÏêÇé
Lexmark£¨ÀûÃË£©ÊÇÒ»¼ÒרעÓÚ´òÓ¡ºÍÓ°Ïñ½â¾ö¼Æ»®µÄÑз¢ÉÌ¡¢Éú²úÉ̼°¹©Ó¦ÉÌ£¬£¬£¬Æä¿Í»§°üÀ¨ÁãÊÛ¡¢½ðÈÚЧÀÍ¡¢Ò½ÁƱ£½¡¡¢ÖÆÔì¡¢½ÌÓýºÍÕþ¸®µÈ£¬£¬£¬Æä´òÓ¡»úÔÚÈ«Çò¹æÄ£ÄÚ±»ÆÕ±éʹÓᣡ£¡£¡£¡£¡£
2021Äê06ÔÂ21ÈÕ£¬£¬£¬ÍâÑóÇå¾²Ñо¿Ô±ÔÚLexmark´òÓ¡»úÈí¼þG2×°ÖðüÖз¢Ã÷ÁËÒ»¸öí§Òâ´úÂëÖ´ÐÐ0dayÎó²î£¬£¬£¬ÆäCVSSv3»ù±¾ÆÀ·ÖΪ8.4¡£¡£¡£¡£¡£¡£
ÖÎÀíÔ±¿É×Ô½ç˵G2×°ÖðüµÄ×°Ö÷¾¶£¬£¬£¬LM__bdsvc.exeÊÇ´òÓ¡»úͨѶϵͳµÄÒ»²¿·Ö¡£¡£¡£¡£¡£¡£ÓÉÓÚLM__bdsvc Öб£´æÒ»¸öδ¼ÓÒýºÅµÄЧÀÍ·¾¶Îó²î£¬£¬£¬¹¥»÷Õß¿ÉÒÔͨ¹ý½«Ò»¸ö¿ÉÖ´ÐÐÎļþ²åÈëЧÀÍ·¾¶À´Ê¹ÓôËÎó²î£¬£¬£¬µ±Ð§ÀÍ»òÏµÍ³ÖØÐÂÆô¶¯Ê±£¬£¬£¬½«ÌáÉý¿ÉÖ´ÐÐÎļþµÄȨÏÞ¡£¡£¡£¡£¡£¡£¸ÃÎó²îÎÞÐèÌØÊâȨÏÞºÍÓû§½»»¥¼´¿ÉÍâµØÊ¹Ó㬣¬£¬ÇÒʹÓÃÖØÆ¯ºóµÍ¡£¡£¡£¡£¡£¡£
0x02 ´¦Öóͷ£½¨Òé
ÏÖÔÚ£¬£¬£¬¸ÃÎó²îÒÑÔÚIBM X-Force£¨»ùÓÚÔÆµÄÍþвÇ鱨¹²ÏíÆ½Ì¨£©¹ûÕæÅû¶£¬£¬£¬µ«LexmarkÔÝδÐÞ¸´¸ÃÎó²î£¬£¬£¬ÇÒÔÝδÐû²¼Ïà¹ØÇ徲ͨ¸æ¡£¡£¡£¡£¡£¡£
¹Ù·½Á´½Ó£º
https://www.lexmark.com/en_us/solutions/security/lexmark-security-advisories.html
0x03 ²Î¿¼Á´½Ó
https://exchange.xforce.ibmcloud.com/vulnerabilities/204093
https://www.lexmark.com/en_us/solutions/security/lexmark-security-advisories.html
https://threatpost.com/lexmark-printers-code-execution-zero-day/167111/
0x04 ʱ¼äÏß
2021-06-21 IBM X-Force¹ûÕæÅû¶
2021-06-23 VSRCÐû²¼Ç徲ͨ¸æ
0x05 ¸½Â¼
CVSSÆÀ·Ö±ê×¼¹ÙÍø£ºhttp://www.first.org/cvss/