TL;DR

Heap-based buffer overflow in Lexmark CX532adwe allows remote attackers to execute arbitrary code without authentication.

What happened

['Network-adjacent attacker exploits heap-based buffer overflow', 'Remote code execution possible on affected printers']

Why it matters for ops

['Buffer overflow can lead to unauthorized system access', 'No auth needed for exploitation']

Mitigation

  • Update firmware to latest version with security patches
  • Implement strict network segmentation around vulnerable devices

Action items

  • Identify and patch all instances of affected hardware
  • Monitor for unusual activity on network segments containing the printers

Detection IOCs

  • Abnormal network traffic to or from Lexmark device IP addresses
  • Unexpected heap memory allocation errors in logs

Source link

http://www.zerodayinitiative.com/advisories/ZDI-26-064/