Lexmark´òÓ¡»úÈÎÒâ´úÂëÖ´ÐÐ0day©¶´
Ðû²¼Ê±¼ä 2021-06-230x00 ©¶´¸ÅÊö
CVE ID | ʱ ¼ä | 2021-06-23 | |
Àà ÐÍ | µ±µØ´úÂëÖ´ÐÐ | µÈ ¼¶ | ¸ßΣ |
Ô¶³ÌÀûÓà | ·ñ | Ó°Ï췶Χ | |
¹¥»÷ÅÓ´ó¶È | µÍ | ¿ÉÓÃÐÔ | ¸ß |
Óû§½»»¥ | ÎÞ | ËùÐèȨÏÞ | ÎÞ |
PoC/EXP | δ¹ûÈ» | ÔÚÒ°ÀûÓà | ·ñ |
0x01 ©¶´ÏêÇé
Lexmark£¨ÀûÃË£©ÊÇÒ»¼ÒרעÓÚ´òÓ¡ºÍÓ°Ïñ½â¾ö·½°¸µÄÑз¢ÉÌ¡¢Éú²úÉ̼°¹©Ó¦ÉÌ£¬Æä¿Í»§°üÂÞÁãÊÛ¡¢½ðÈÚ·þÎñ¡¢Ò½ÁƱ£½¡¡¢ÖÆÔì¡¢½ÌÓýºÍÕþ¸®µÈ£¬Æä´òÓ¡»úÔÚÈ«Çò·¶Î§ÄÚ±»¹ã·ºÊ¹Óá£
2021Äê06ÔÂ21ÈÕ£¬¹úÍâÄþ¾²Ñо¿Ô±ÔÚLexmark´òÓ¡»úÈí¼þG2°²×°°üÖз¢ÏÖÁËÒ»¸öÈÎÒâ´úÂëÖ´ÐÐ0day©¶´£¬ÆäCVSSv3»ù±¾ÆÀ·ÖΪ8.4¡£
¹ÜÀíÔ±¿É×Ô½ç˵G2°²×°°üµÄ°²×°Â·¾¶£¬LM__bdsvc.exeÊÇ´òÓ¡»úͨÐÅϵͳµÄÒ»²¿ÃÅ¡£ÓÉÓÚLM__bdsvc ÖдæÔÚÒ»¸öδ¼ÓÒýºÅµÄ·þÎñ·¾¶Â©¶´£¬¹¥»÷Õß¿ÉÒÔͨ¹ý½«Ò»¸ö¿ÉÖ´ÐÐÎļþ²åÈë·þÎñ·¾¶À´ÀûÓôË©¶´£¬µ±·þÎñ»òÏµÍ³ÖØÐÂÆô¶¯Ê±£¬½«ÌáÉý¿ÉÖ´ÐÐÎļþµÄȨÏÞ¡£¸Ã©¶´ÎÞÐèÌØÊâȨÏÞºÍÓû§½»»¥¼´¿Éµ±µØÀûÓã¬ÇÒÀûÓÃÅÓ´ó¶ÈµÍ¡£
0x02 ´¦Öý¨Òé
Ŀǰ£¬¸Ã©¶´ÒÑÔÚIBM X-Force£¨»ùÓÚÔÆµÄÍþвÇ鱨¹²ÏíÆ½Ì¨£©¹ûÈ»Åû¶£¬µ«LexmarkÔÝδÐÞ¸´¸Ã©¶´£¬ÇÒÔÝδÐû²¼Ïà¹ØÄþ¾²Í¨¸æ¡£
¹Ù·½Á´½Ó£º
https://www.lexmark.com/en_us/solutions/security/lexmark-security-advisories.html
0x03 ²Î¿¼Á´½Ó
https://exchange.xforce.ibmcloud.com/vulnerabilities/204093
https://www.lexmark.com/en_us/solutions/security/lexmark-security-advisories.html
https://threatpost.com/lexmark-printers-code-execution-zero-day/167111/
0x04 ʱ¼äÏß
2021-06-21 IBM X-Force¹ûÈ»Åû¶
2021-06-23 VSRCÐû²¼Äþ¾²Í¨¸æ
0x05 ¸½Â¼
CVSSÆÀ·Ö³ß¶È¹ÙÍø£ºhttp://www.first.org/cvss/