Lexmark´òÓ¡»úËÁÒâ´úÂëÖ´ÐÐ0day·ì϶
°ä²¼¹¦·ò 2021-06-230x00 ·ì϶¸ÅÊö
CVE ID | ʱ ¼ä | 2021-06-23 | |
Àà ÐÍ | ±¾µØ´úÂëÖ´ÐÐ | µÈ ¼¶ | ¸ßΣ |
Ô¶³ÌÀûÓà | ·ñ | Ó°ÏìÁìÓò | |
¹¥»÷¸´ÔÓ¶È | µÍ | ¿ÉÓÃÐÔ | ¸ß |
Óû§½»»¥ | ÎÞ | ËùÐèȨÏÞ | ÎÞ |
PoC/EXP | δ¹«¿ª | ÔÚÒ°ÀûÓà | ·ñ |
0x01 ·ì϶ÏêÇé

Lexmark£¨ÀûÃË£©ÊÇÒ»¼ÒרһÓÚ´òÓ¡ºÍÓ°Ïñ½â¾ö¹æ»®µÄÑз¢ÉÌ¡¢³ö²úÉ̼°¹©¸øÉÌ£¬Æä¿Í»§Ô̺¬ÁãÊÛ¡¢½ðÈÚ·þÎñ¡¢Ò½ÁƱ£½¡¡¢Ôì×÷¡¢½ÌÓýºÍµ±¾ÖµÈ£¬Æä´òÓ¡»úÔÚÈ«ÇòÁìÓòÄÚ±»¿í·ºÊ¹Óá£
2021Äê06ÔÂ21ÈÕ£¬¹ú±í°²È«×êÑÐÔ±ÔÚLexmark´òÓ¡»úÈí¼þG2×°ÖðüÖз¢ÏÖÁËÒ»¸öËÁÒâ´úÂëÖ´ÐÐ0day·ì϶£¬ÆäCVSSv3¸ù»ùÆÀ·ÖΪ8.4¡£
ÖÎÀíÔ±¿É×Ô½ç˵G2×°ÖðüµÄ×°ÖÃõè¾¶£¬LM__bdsvc.exeÊÇ´òÓ¡»úͨѶϵͳµÄÒ»²¿ÃÅ¡£ÓÉÓÚLM__bdsvc ÖдæÔÚÒ»¸öδ¼ÓÒýºÅµÄ·þÎñõè¾¶·ì϶£¬¹¥»÷ÕßÄܹ»Í¨¹ý½«Ò»¸ö¿ÉÖ´ÐÐÎļþ²åÈë·þÎñõè¾¶À´ÀûÓô˷ì϶£¬µ±·þÎñ»òϵͳ³ÁÐÂÆô¶¯Ê±£¬½«ÌáÉý¿ÉÖ´ÐÐÎļþµÄȨÏÞ¡£¸Ã·ì϶ÎÞÐèÌØÊâȨÏÞºÍÓû§½»»¥¼´¿É±¾µØÀûÓã¬ÇÒÀûÓø´ÔӶȵ͡£
0x02 ´ëÖý¨Òé
Ŀǰ£¬¸Ã·ì϶ÒÑÔÚIBM X-Force£¨»ùÓÚÔÆµÄÍþвµý±¨¹²ÏíÆ½Ì¨£©¹«¿ªÅû¶£¬µ«LexmarkÔÝ佨¸´¸Ã·ì϶£¬ÇÒÔÝδ°ä²¼Óйذ²È«²¼¸æ¡£
¹Ù·½Á´½Ó£º
https://www.lexmark.com/en_us/solutions/security/lexmark-security-advisories.html
0x03 ²Î¿¼Á´½Ó
https://exchange.xforce.ibmcloud.com/vulnerabilities/204093
https://www.lexmark.com/en_us/solutions/security/lexmark-security-advisories.html
https://threatpost.com/lexmark-printers-code-execution-zero-day/167111/
0x04 ¹¦·òÏß
2021-06-21 IBM X-Force¹«¿ªÅû¶
2021-06-23 VSRC°ä²¼°²È«¹«¸æ
0x05 ¸½Â¼
CVSSÆÀ·Ö³ß¶È¹ÙÍø£ºhttp://www.first.org/cvss/



¾©¹«Íø°²±¸11010802024551ºÅ