CVE-2021-35449

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
19/07/2021
Last modified:
20/09/2021

Description

The Lexmark Universal Print Driver version 2.15.1.0 and below, G2 driver 2.7.1.0 and below, G3 driver 3.2.0.0 and below, and G4 driver 4.2.1.0 and below are affected by a privilege escalation vulnerability. A standard low priviliged user can use the driver to execute a DLL of their choosing during the add printer process, resulting in escalation of privileges to SYSTEM.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:lexmark:g2_driver:*:*:*:*:*:*:*:* 2.7.1.0 (including)
cpe:2.3:a:lexmark:g3_driver:*:*:*:*:*:*:*:* 3.2.0.0 (including)
cpe:2.3:a:lexmark:g4_driver:*:*:*:*:*:*:*:* 4.2.1.0 (including)
cpe:2.3:a:lexmark:universal_print_driver:*:*:*:*:*:*:*:* 2.15.1.0 (including)