HIGH

CVE-2021-35449

CVSS v3

7.8

HIGH

EPSS Score

13.3%

exploit probability

CISA KEV

No

known exploited

Exploitation

SSVC status

Description

The Lexmark Universal Print Driver version 2.15.1.0 and below, G2 driver 2.7.1.0 and below, G3 driver 3.2.0.0 and below, and G4 driver 4.2.1.0 and below are affected by a privilege escalation vulnerability. A standard low priviliged user can use the driver to execute a DLL of their choosing during the add printer process, resulting in escalation of privileges to SYSTEM.

Technical details

Published
7/19/2021

Frequently asked questions

What is CVE-2021-35449?

The Lexmark Universal Print Driver version 2.15.1.0 and below, G2 driver 2.7.1.0 and below, G3 driver 3.2.0.0 and below, and G4 driver 4.2.1.0 and below are affected by a privilege escalation vulnerability. A standard low priviliged user can use the driver to execute a DLL of their choosing during the add printer process, resulting in escalation of privileges to SYSTEM.

Is CVE-2021-35449 actively exploited?

Active exploitation of CVE-2021-35449 has not been confirmed. The EPSS score is 13.3%, indicating the estimated probability of exploitation in the next 30 days.

What is the CVSS score for CVE-2021-35449?

CVE-2021-35449 has a CVSS v3 base score of 7.8 (HIGH severity).

Is CVE-2021-35449 affecting your environment?

Use isMalicious to check if any of your IPs or domains are associated with this vulnerability's IOCs.