← back
CVE-2023-24884highCWE-681

Microsoft PostScript and PCL6 Class Printer Driver Remote Code Execution Vulnerability

21Vexday Risk Score

No sign of exploitation. No public exploitation artifact known so far.

ssvc Trackcvss 8.8epss 1.6%
exploitation probability
1.6%top 25% of all CVEs
observed exploitation
nono source reports it
In short

A flaw in Microsoft's printer drivers allows an attacker to execute malicious code on a computer by sending specially crafted print jobs. This affects PostScript and PCL6 printers and can compromise system security.

Technical detail

The vulnerability exists in the PostScript and PCL6 class printer drivers due to improper validation of print job data (CWE-681: Integer Overflow or Wraparound). An attacker can send a malicious print job through the network or local print queue to trigger memory corruption, leading to remote code execution with system privileges.

Summary generated and translated by AI from the official description.
Microsoft PostScript and PCL6 Class Printer Driver Remote Code Execution Vulnerability
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H/E:U/RL:O/RC:C