CVE-2024-0244 – A heap buffer overflow in the Canon MF753Cdw printer
ZDI details CVE-2024-0244, an unauthenticated heap overflow in the Canon MF753Cdw exploited at Pwn2Own.
A Zero Day Initiative retrospective describes CVE-2024-0244, an unauthenticated heap-based buffer overflow in the Canon MF753Cdw printer that leads to an arbitrary free(). The flaw is in parsing a binary fax job sent over SOAP to the printer's print service, where an unchecked destination-number length overflows a heap object. The author, who previously targeted the similar MF743Cdw, outlines contest exploitation using Canon's BJNP protocol to place shellcode in RWX memory, but says the precise root cause was never identified. The issue was prepared for Pwn2Own Toronto 2023 and is not described as ongoing exploitation.