Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2021-38085

Опубликовано: 11 авг. 2021
Источник: nvd
CVSS3: 7.8
CVSS2: 7.2
EPSS Низкий

Описание

The Canon TR150 print driver through 3.71.2.10 is vulnerable to a privilege escalation issue. During the add printer process, a local attacker can overwrite CNMurGE.dll and, if timed properly, the overwritten DLL will be loaded into a SYSTEM process resulting in escalation of privileges. This occurs because the driver drops a world-writable DLL into a CanonBJ %PROGRAMDATA% location that gets loaded by printisolationhost (a system process).

Уязвимые конфигурации

Конфигурация 1

Одновременно

cpe:2.3:o:canon:pixma_tr150_firmware:*:*:*:*:*:*:*:*
Версия до 3.71.2.10 (включая)
cpe:2.3:h:canon:pixma_tr150:-:*:*:*:*:*:*:*

EPSS

Процентиль: 88%
0.03671
Низкий

7.8 High

CVSS3

7.2 High

CVSS2

Дефекты

CWE-732

Связанные уязвимости

CVSS3: 7.8
github
больше 3 лет назад

The Canon TR150 print driver through 3.71.2.10 is vulnerable to a privilege escalation issue. During the add printer process, a local attacker can overwrite CNMurGE.dll and, if timed properly, the overwritten DLL will be loaded into a SYSTEM process resulting in escalation of privileges. This occurs because the driver drops a world-writable DLL into a CanonBJ %PROGRAMDATA% location that gets loaded by printisolationhost (a system process).

EPSS

Процентиль: 88%
0.03671
Низкий

7.8 High

CVSS3

7.2 High

CVSS2

Дефекты

CWE-732