A heap corruption vulnerability has been identified in PostScript interpreter in various Lexmark devices. The vulnerability can be leveraged by an attacker to execute arbitrary code.
The vulnerability consists of heap memory corruption during input data processing by the PostScript interpreter. An attacker can submit a crafted document or PostScript data that triggers incorrect memory operations. As a result, arbitrary code execution is possible in the context of the vulnerable device. The vulnerability is classified as CWE-465, which indicates errors related to improper pointer or memory management.
An attacker can execute arbitrary code on a vulnerable Lexmark device, which may lead to full device takeover, leakage of processed data, and use of the device as an access point to the internal network.
Patches available from the manufacturer should be applied in accordance with references published on the Lexmark Security Advisories page (https://www.lexmark.com/en_us/solutions/security/lexmark-security-advisories.html). Additionally, it is recommended to restrict network access to printing devices at the firewall level and disable unnecessary network services.
Various Lexmark devices equipped with a PostScript interpreter — specific models indicated in the manufacturer's references (https://www.lexmark.com/en_us/solutions/security/lexmark-security-advisories.html)
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H