CVE-2021-35449
The Lexmark Universal Print Driver version 2.15.1.0 and below, G2 driver 2.7.1.0 and below, G3 driver 3.2.0.0 and below, and G4 driver 4.2.1.0 and below are affected by a privilege escalation vulnerability. A standard low priviliged user can use the driver to execute a DLL of their choosing during the add printer process, resulting in escalation of privileges to SYSTEM.
- Affected products
- G2 Driver, G3 Driver, G4 Driver, Lexmark Universal Print Driver
- Lexmark g2 Driver
- ≤ 2.7.1.0
- Lexmark g3 Driver
- ≤ 3.2.0.0
- Lexmark g4 Driver
- ≤ 4.2.1.0
- Lexmark Universal Print Driver
- ≤ 2.15.1.0
- Fix
- Available
- CVSS 3.1
- 7.8 HIGH
- EPSS
- 1.4% (70th percentile)
- Weakness
- CWE-732
- NVD status
- Modified
- Published
- 2021-07-19
CVE-2021-35449 at NVD
4 known exploits for CVE-2021-35449
Proof-of-concept code and exploit modules indexed by Sploitus