/lexmark

Primary LanguagePython

lexmark printer haxx

I made an entry for Pwn2Own Toronto 2022, that magically failed during the actual competition. ZDI offered to buy the bug(s) anyway for a laughable monetary amount and I promptly forgot about their offer.

Here is a small archive with exploit, writeup and tools.

Exploit was tested against the Lexmark 'MC3224adwe' but is reported to work against other printers/copiers as well. ;-)

This is all still "0day" at the time of writing (2023-01-10, tested against firmware CXLBL.081.225)

Everything is distributed as-is, don't expect support/updates.

Enjoy!

-- blasty peter@haxx.in