Remote execution exploit chain in CUPS: Overview, detection, and remediation
ID: 52bc5467-36f7-557c-a20a-35b8a1040e37
STIX ID: report--52bc5467-36f7-557c-a20a-35b8a1040e37
Feed Name: Datadog Security Labs
Datadog Security Labs describes a chained set of CUPS vulnerabilities that can cause CUPS to bind to all interfaces and accept attacker-controlled printer definitions over UDP port 631, enabling remote code execution when a user initiates a print job; the disclosure includes PoCs, observed scanning and exploitation attempts with IoCs (IP addresses and printer URLs), and recommended mitigations such as updating, disabling cups-browsed, and blocking UDP/631 from untrusted networks.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
