ZeroHour
Schneier on Securitypublished ()ingested Bruce Schneier

Nasty Windows Printer Driver Vulnerability

criticalVulnerabilityimportance 60CVE-2021-3438

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2021-3438
A potential buffer overflow in the software drivers for certain HP LaserJet products and Samsung product printers could lead to an escalation of privilege.

A potential buffer overflow in the software drivers for certain HP LaserJet products and Samsung product printers could lead to an escalation of privilege.

NVD description · AI analysis pending
7.83%
  • hp color laser 150 4zb94a
  • hp color laser 150 4zb95a
  • hp color laser mfp 170 4zb96a
  • +1 more
Full article155 words · extracted from schneier.com · click to collapse

From SentinelLabs, a critical vulnerability in HP printer drivers:

Researchers have released technical details on a high-severity privilege-escalation flaw in HP printer drivers (also used by Samsung and Xerox), which impacts hundreds of millions of Windows machines.

If exploited, cyberattackers could bypass security products; install programs; view, change, encrypt or delete data; or create new accounts with more extensive user rights.

The bug (CVE-2021-3438) has lurked in systems for 16 years, researchers at SentinelOne said, but was only uncovered this year. It carries an 8.8 out of 10 rating on the CVSS scale, making it high-severity.

Look for your printer here, and download the patch if there is one.

EDITED TO ADD (8/13): Here’s a better list of affected HP and Samsung printers.

Tags: cyberattack, HP, printers, privilege escalation, vulnerabilities

Posted on July 22, 2021 at 10:41 AM42 Comments

Sidebar photo of Bruce Schneier by Joe MacInnis.

Text extracted automatically; images, tables and formatting may be missing. Original: https://www.schneier.com/blog/archives/2021/07/nasty-printer-driver-vulnerability.html