ZeroHour

CVE-2024-2209

CVSS 3.1
6.3 medium
EPSS
<1%p11
Published
()
Modified
Description

A user with administrative privileges can create a compromised dll file of the same name as the original dll within the HP printer’s Firmware Update Utility (FUU) bundle and place it in the Microsoft Windows default downloads directory which can lead to potential arbitrary code execution.

Vendors
hp
Products
26k70b firmware, 297x1a firmware, 2a9q5a firmware, 26k72a firmware, 26k69a firmware, 26k70a firmware, 26k71a firmware, 26k68a firmware, 26k67a firmware, 3xv19a firmware, 7fr52a firmware, 7fr57a firmware
Weakness
CWE-94
Vector
CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:L

In the news

No ingested article mentions this CVE yet.