Lexmark´òÓ¡»úí§Òâ´úÂëÖ´ÐÐ0dayÎó²î

Ðû²¼Ê±¼ä 2021-06-23

0x00 Îó²î¸ÅÊö

CVE    ID


ʱ      ¼ä

2021-06-23

Àà      ÐÍ

ÍâµØ´úÂëÖ´ÐÐ

µÈ      ¼¶

¸ßΣ

Ô¶³ÌʹÓÃ

·ñ

Ó°Ïì¹æÄ£


¹¥»÷ÖØÆ¯ºó

µÍ

¿ÉÓÃÐÔ

¸ß

Óû§½»»¥

ÎÞ

ËùÐèȨÏÞ

ÎÞ

PoC/EXP

δ¹ûÕæ

ÔÚҰʹÓÃ

·ñ

 

0x01 Îó²îÏêÇé

image.png

Lexmark£¨ÀûÃË£©ÊÇÒ»¼ÒרעÓÚ´òÓ¡ºÍÓ°Ïñ½â¾ö¼Æ»®µÄÑз¢ÉÌ¡¢Éú²úÉ̼°¹©Ó¦ÉÌ£¬£¬£¬£¬£¬Æä¿Í»§°üÀ¨ÁãÊÛ¡¢½ðÈÚЧÀÍ¡¢Ò½ÁƱ£½¡¡¢ÖÆÔì¡¢½ÌÓýºÍÕþ¸®µÈ£¬£¬£¬£¬£¬Æä´òÓ¡»úÔÚÈ«Çò¹æÄ£ÄÚ±»ÆÕ±éʹÓᣡ£¡£¡£¡£¡£ ¡£¡£

2021Äê06ÔÂ21ÈÕ£¬£¬£¬£¬£¬ÍâÑóÇå¾²Ñо¿Ô±ÔÚLexmark´òÓ¡»úÈí¼þG2×°ÖðüÖз¢Ã÷ÁËÒ»¸öí§Òâ´úÂëÖ´ÐÐ0dayÎó²î£¬£¬£¬£¬£¬ÆäCVSSv3»ù±¾ÆÀ·ÖΪ8.4¡£¡£¡£¡£¡£¡£ ¡£¡£

ÖÎÀíÔ±¿É×Ô½ç˵G2×°ÖðüµÄ×°Ö÷¾¶£¬£¬£¬£¬£¬LM__bdsvc.exeÊÇ´òÓ¡»úͨѶϵͳµÄÒ»²¿·Ö¡£¡£¡£¡£¡£¡£ ¡£¡£ÓÉÓÚLM__bdsvc Öб£´æÒ»¸öδ¼ÓÒýºÅµÄЧÀÍ·¾¶Îó²î£¬£¬£¬£¬£¬¹¥»÷Õß¿ÉÒÔͨ¹ý½«Ò»¸ö¿ÉÖ´ÐÐÎļþ²åÈëЧÀÍ·¾¶À´Ê¹ÓôËÎó²î£¬£¬£¬£¬£¬µ±Ð§ÀÍ»òÏµÍ³ÖØÐÂÆô¶¯Ê±£¬£¬£¬£¬£¬½«ÌáÉý¿ÉÖ´ÐÐÎļþµÄȨÏÞ¡£¡£¡£¡£¡£¡£ ¡£¡£¸ÃÎó²îÎÞÐèÌØÊâȨÏÞºÍÓû§½»»¥¼´¿ÉÍâµØÊ¹Ó㬣¬£¬£¬£¬ÇÒʹÓÃÖØÆ¯ºóµÍ¡£¡£¡£¡£¡£¡£ ¡£¡£

 

0x02 ´¦Öóͷ£½¨Òé

ÏÖÔÚ£¬£¬£¬£¬£¬¸ÃÎó²îÒÑÔÚIBM X-Force£¨»ùÓÚÔÆµÄÍþвÇ鱨¹²ÏíÆ½Ì¨£©¹ûÕæÅû¶£¬£¬£¬£¬£¬µ«LexmarkÔÝδÐÞ¸´¸ÃÎó²î£¬£¬£¬£¬£¬ÇÒÔÝδÐû²¼Ïà¹ØÇ徲ͨ¸æ¡£¡£¡£¡£¡£¡£ ¡£¡£

¹Ù·½Á´½Ó£º

https://www.lexmark.com/en_us/solutions/security/lexmark-security-advisories.html

 

0x03 ²Î¿¼Á´½Ó

https://exchange.xforce.ibmcloud.com/vulnerabilities/204093

https://www.lexmark.com/en_us/solutions/security/lexmark-security-advisories.html

https://threatpost.com/lexmark-printers-code-execution-zero-day/167111/

 

0x04 ʱ¼äÏß

2021-06-21  IBM X-Force¹ûÕæÅû¶

2021-06-23  VSRCÐû²¼Ç徲ͨ¸æ

 

0x05 ¸½Â¼

CVSSÆÀ·Ö±ê×¼¹ÙÍø£ºhttp://www.first.org/cvss/

image.png