Buffer overflow in XML processing of XPS file in Small Office Multifunction Printers and Laser Printers(*) which may allow an attacker on the network segment to trigger the affected product being unresponsive or to execute arbitrary code. *: Satera LBP670C Series/Satera MF750C Series firmware v06.02 and earlier sold in Japan.Color imageCLASS LBP630C/Color imageCLASS MF650C Series/imageCLASS LBP230 Series/imageCLASS X LBP1238 II/imageCLASS MF450 Series/imageCLASS X MF1238 II/imageCLASS X MF1643i II/imageCLASS X MF1643iF II firmware v06.02 and earlier sold in US.i-SENSYS LBP630C Series/i-SENSYS MF650C Series/i-SENSYS LBP230 Series/1238P II/1238Pr II/i-SENSYS MF450 Series/i-SENSYS MF550 Series/1238i II/1238iF II/imageRUNNER 1643i II/imageRUNNER 1643iF II firmware v06.02 and earlier sold in Europe.
The attacker sends a specially crafted XPS file containing maliciously constructed XML data to the device. During parsing of this file, a buffer overflow occurs (CWE-787 — out-of-bounds write in process memory), leading to memory corruption of the print job handling process. The error occurs without authentication requirement, and the attack itself is possible for any host in the same network segment as the device.
An attacker can cause permanent device unavailability (hang or restart) or execute arbitrary code (RCE) in the context of the printer firmware, which may result in complete takeover of the device.
Firmware on devices should be updated to a version newer than v06.02. Patches and detailed update instructions are available in official Canon security communications: for Japan at canon.jp/support, for USA at usa.canon.com, for Europe at canon-europe.com and in the Canon PSIRT bulletin (cp2026-001). Until the patch is implemented, it is recommended to isolate devices on the network (e.g., dedicated VLAN segment or firewall) so that only trusted hosts have access to the printers.
Canon devices with firmware version v06.02 and earlier: Satera LBP670C Series / Satera MF750C Series (Japan); Color imageCLASS LBP630C / Color imageCLASS MF650C Series / imageCLASS LBP230 Series / imageCLASS X LBP1238 II / imageCLASS MF450 Series / imageCLASS X MF1238 II / imageCLASS X MF1643i II / imageCLASS X MF1643iF II (USA); i-SENSYS LBP630C Series / i-SENSYS MF650C Series / i-SENSYS LBP230 Series / 1238P II / 1238Pr II / i-SENSYS MF450 Series / i-SENSYS MF550 Series / 1238i II / 1238iF II / imageRUNNER 1643i II / imageRUNNER 1643iF II (Europe). Products listed in metadata: Canon MF455DW, MF453DW, MF452DW and their firmware.
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:XCanon Lbp1238 Ii
HWCanonall versionsCanon Lbp1238 Ii Firmware
OSCanon≤ 06.02Canon Lbp236dw
HWCanonall versionsCanon Lbp236dw Firmware
OSCanon≤ 06.02Canon Lbp237dw
HWCanonall versionsCanon Lbp237dw Firmware
OSCanon≤ 06.02Canon Lbp632cdw
HWCanonall versionsCanon Lbp632cdw Firmware
OSCanon≤ 06.02Canon Lbp633cdw
HWCanonall versionsCanon Lbp633cdw Firmware
OSCanon≤ 06.02Canon Mf1238 Ii
HWCanonall versionsCanon Mf1238 Ii Firmware
OSCanon≤ 06.02Canon Mf1643if Ii
HWCanonall versionsCanon Mf1643if Ii Firmware
OSCanon≤ 06.02Canon Mf1643i Ii
HWCanonall versionsCanon Mf1643i Ii Firmware
OSCanon≤ 06.02Canon Mf451dw
HWCanonall versionsCanon Mf451dw Firmware
OSCanon≤ 06.02Canon Mf452dw
HWCanonall versionsCanon Mf452dw Firmware
OSCanon≤ 06.02Canon Mf453dw
HWCanonall versionsCanon Mf453dw Firmware
OSCanon≤ 06.02Canon Mf455dw
HWCanonall versionsCanon Mf455dw Firmware
OSCanon≤ 06.02Canon Mf652cdw
HWCanonall versionsCanon Mf652cw Firmware
OSCanon≤ 06.02Canon Mf653cdw
HWCanonall versionsCanon Mf653cdw Firmware
OSCanon≤ 06.02Canon Mf654cdw
HWCanonall versionsCanon Mf654cdw Firmware
OSCanon≤ 06.02
Related vulnerabilities
Buffer overflow w przetwarzaniu czcionek XPS w drukarkach Canon — RCE
Buffer overflow w Canon — RCE przez WSD w drukarkach biurowych
RCE przez invalid free w drukarkach Canon — luki w firmware v06.02
Buffer overflow w drukarkach Canon — RCE przez sieć lokalną
Buffer overflow w drukarkach Canon — RCE przez sieć lokalną