TL;DR

["Lexmark CX532adwe printer's esfhelper component has a critical privilege escalation flaw.", 'CVE-2025-65078, CVSS: 7.8']

What happened

['Local attackers can escalate privileges on affected Lexmark CX532adwe printers by exploiting an untrusted search path vulnerability in the esfhelper component.']

Why it matters for ops

['Attackers need to execute low-privileged code initially, but this flaw allows for privilege escalation.']

Mitigation

  • Update to the latest firmware version
  • Limit user privileges on networked printers
  • Implement network segmentation for sensitive devices

Action items

  • Audit existing Lexmark CX532adwe printer deployments
  • Apply vendor-provided patches immediately
  • Review and enforce least privilege access controls

Detection IOCs

  • Unusual system calls from esfhelper
  • Unexpected changes in file permissions

Source link

http://www.zerodayinitiative.com/advisories/ZDI-26-062/