HomeSecurity16-year-old bug in "printer software" gives hackers admin rights

16-year-old bug in “printer software” gives hackers admin rights

A 16-year-old security vulnerability (bug) found in HP, Xerox and Samsung printer software allows attackers to gain administrator privileges on systems using the vulnerable driver software.

printer software bug

See also: Google Chrome: Eighth zero-day bug fixed in six months

“This high-severity vulnerability, which has existed in HP, Samsung, and Xerox printer software since 2005, affects hundreds of millions of devices and millions of users worldwide,” according to a SentinelOne report published today.

The security flaw tracked as CVE-2021-3438 is a buffer overflow in the SSPORT.SYS driver for specific printer models that could lead to local user privilege.

As the researchers discovered, the "buggy driver" is automatically installed with the printer software and will be loaded by Windows after each system restart.

See also: SolarWinds hackers: Use iOS zero-day bug to compromise updated iPhones

This makes it the ideal target for attackers who need an easy way to escalate privileges, as the bug can be abused even when the printer is not connected to the targeted device.

Successful exploitation requires local user access, which means threat actors would first need to gain access to the targeted devices.

Once this is achieved, they can abuse the security flaw to escalate privileges in low-sophistication attacks without requiring user interaction.

The result is that attackers with basic user rights can elevate their privileges to SYSTEM and execute code in "kernel mode", potentially bypassing security products that would block their attacks or the delivery of additional malicious payloads.

See also: Chinese hackers exploit SolarWinds bug to target defense companies

Users were urged to update as soon as possible

A list of affected printer models using the vulnerable driver can be found in HP's security advisory and in this Xerox security mini-bulletin

Business and home customers of HP, Xerox, and Samsung are urged to apply the patches provided by the two vendors as soon as possible.

Information source: bleepingcomputer.com

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

Teo Ehc
Teo Ehchttps://www.secnews.gr
Be the limited edition.

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS