Lexmark´òÓ¡»úí§Òâ´úÂëÖ´ÐÐ0dayÎó²î
Ðû²¼Ê±¼ä 2021-06-230x00 Îó²î¸ÅÊö
CVE ID | ʱ ¼ä | 2021-06-23 | |
Àà ÐÍ | ÍâµØ´úÂëÖ´ÐÐ | µÈ ¼¶ | ¸ßΣ |
Ô¶³ÌʹÓà | ·ñ | Ó°Ïì¹æÄ£ | |
¹¥»÷ÖØÆ¯ºó | µÍ | ¿ÉÓÃÐÔ | ¸ß |
Óû§½»»¥ | ÎÞ | ËùÐèȨÏÞ | ÎÞ |
PoC/EXP | δ¹ûÕæ | ÔÚҰʹÓà | ·ñ |
0x01 Îó²îÏêÇé

Lexmark£¨ÀûÃË£©ÊÇÒ»¼ÒרעÓÚ´òÓ¡ºÍÓ°Ïñ½â¾ö¼Æ»®µÄÑз¢ÉÌ¡¢Éú²úÉ̼°¹©Ó¦ÉÌ£¬£¬£¬£¬£¬Æä¿Í»§°üÀ¨ÁãÊÛ¡¢½ðÈÚЧÀÍ¡¢Ò½ÁƱ£½¡¡¢ÖÆÔì¡¢½ÌÓýºÍÕþ¸®µÈ£¬£¬£¬£¬£¬Æä´òÓ¡»úÔÚÈ«Çò¹æÄ£ÄÚ±»ÆÕ±éʹÓᣡ£¡£¡£¡£¡£¡£¡£
2021Äê06ÔÂ21ÈÕ£¬£¬£¬£¬£¬ÍâÑóÇå¾²Ñо¿Ô±ÔÚLexmark´òÓ¡»úÈí¼þG2×°ÖðüÖз¢Ã÷ÁËÒ»¸öí§Òâ´úÂëÖ´ÐÐ0dayÎó²î£¬£¬£¬£¬£¬ÆäCVSSv3»ù±¾ÆÀ·ÖΪ8.4¡£¡£¡£¡£¡£¡£¡£¡£
ÖÎÀíÔ±¿É×Ô½ç˵G2×°ÖðüµÄ×°Ö÷¾¶£¬£¬£¬£¬£¬LM__bdsvc.exeÊÇ´òÓ¡»úͨѶϵͳµÄÒ»²¿·Ö¡£¡£¡£¡£¡£¡£¡£¡£ÓÉÓÚLM__bdsvc Öб£´æÒ»¸öδ¼ÓÒýºÅµÄЧÀÍ·¾¶Îó²î£¬£¬£¬£¬£¬¹¥»÷Õß¿ÉÒÔͨ¹ý½«Ò»¸ö¿ÉÖ´ÐÐÎļþ²åÈëЧÀÍ·¾¶À´Ê¹ÓôËÎó²î£¬£¬£¬£¬£¬µ±Ð§ÀÍ»òÏµÍ³ÖØÐÂÆô¶¯Ê±£¬£¬£¬£¬£¬½«ÌáÉý¿ÉÖ´ÐÐÎļþµÄȨÏÞ¡£¡£¡£¡£¡£¡£¡£¡£¸ÃÎó²îÎÞÐèÌØÊâȨÏÞºÍÓû§½»»¥¼´¿ÉÍâµØÊ¹Ó㬣¬£¬£¬£¬ÇÒʹÓÃÖØÆ¯ºóµÍ¡£¡£¡£¡£¡£¡£¡£¡£
0x02 ´¦Öóͷ£½¨Òé
ÏÖÔÚ£¬£¬£¬£¬£¬¸ÃÎó²îÒÑÔÚIBM X-Force£¨»ùÓÚÔÆµÄÍþвÇ鱨¹²ÏíÆ½Ì¨£©¹ûÕæÅû¶£¬£¬£¬£¬£¬µ«LexmarkÔÝδÐÞ¸´¸ÃÎó²î£¬£¬£¬£¬£¬ÇÒÔÝδÐû²¼Ïà¹ØÇ徲ͨ¸æ¡£¡£¡£¡£¡£¡£¡£¡£
¹Ù·½Á´½Ó£º
https://www.lexmark.com/en_us/solutions/security/lexmark-security-advisories.html
0x03 ²Î¿¼Á´½Ó
https://exchange.xforce.ibmcloud.com/vulnerabilities/204093
https://www.lexmark.com/en_us/solutions/security/lexmark-security-advisories.html
https://threatpost.com/lexmark-printers-code-execution-zero-day/167111/
0x04 ʱ¼äÏß
2021-06-21 IBM X-Force¹ûÕæÅû¶
2021-06-23 VSRCÐû²¼Ç徲ͨ¸æ
0x05 ¸½Â¼
CVSSÆÀ·Ö±ê×¼¹ÙÍø£ºhttp://www.first.org/cvss/



¾©¹«Íø°²±¸11010802024551ºÅ