logo

Remote execution exploit chain in CUPS: Overview, detection, and remediation

ID: 52bc5467-36f7-557c-a20a-35b8a1040e37

STIX ID: report--52bc5467-36f7-557c-a20a-35b8a1040e37

Feed Name: Datadog Security Labs

Threat Score
70/100

Date Published: 2024-09-27

Date Updated: 2026-04-27

...
...

Datadog Security Labs describes a chained set of CUPS vulnerabilities that can cause CUPS to bind to all interfaces and accept attacker-controlled printer definitions over UDP port 631, enabling remote code execution when a user initiates a print job; the disclosure includes PoCs, observed scanning and exploitation attempts with IoCs (IP addresses and printer URLs), and recommended mitigations such as updating, disabling cups-browsed, and blocking UDP/631 from untrusted networks.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.