An untrusted search path vulnerability has been identified in the Embedded Solutions Framework in various Lexmark devices. This vulnerability can be leveraged by an attacker to execute arbitrary code.
The untrusted search path vulnerability (CWE-426) occurs when an application or service searches for and loads resources (such as libraries or executable files) from a path that can be controlled or manipulated by an attacker. In the case of Lexmark devices, the Embedded Solutions Framework component improperly verifies the source of loaded resources. An attacker can place a malicious file or library in a location searched by the framework, leading to execution of attacker-supplied code in the context of the target device.
An attacker can execute arbitrary code on a vulnerable Lexmark device without requiring any privileges, potentially leading to complete device compromise, data breach, or disruption of its operation.
Apply patches available from the vendor according to references published on the Lexmark Security Advisories page (https://www.lexmark.com/en_us/solutions/security/lexmark-security-advisories.html)
Various Lexmark devices equipped with the Embedded Solutions Framework component — the exact list of models is indicated in the vendor's references
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X