CVE-2017-2822
An exploitable code execution vulnerability exists in the image rendering functionality of Lexmark Perceptive Document Filters 11.3.0.2400.
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (2.07%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
An exploitable code execution vulnerability exists in the image rendering functionality of Lexmark Perceptive Document Filters 11.3.0.2400. A specifically crafted PDF can cause a function call on a corrupted DCTStream to occur, resulting in user controlled data being written to the stack. A maliciously crafted PDF file can be used to trigger this vulnerability.
- CVSS 3.0
- 8.8 HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
- EPSS
- 2.07% probability · 80th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-119
- Affected
- lexmark/perceptive document filters
- Source
- talos-cna@cisco.com
References
- http://www.securityfocus.com/bid/100512Third Party Advisory, VDB Entry
- https://www.talosintelligence.com/vulnerability_reports/TALOS-2017-0323Third Party Advisory
- http://www.securityfocus.com/bid/100512Third Party Advisory, VDB Entry
- https://www.talosintelligence.com/vulnerability_reports/TALOS-2017-0323Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.