CVE-2014-8741
Lexmark MarkVision Enterprise GfdFileUploadServlet Remote Code Execution Vulnerability
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
1Exploited in Wild
-Decision
Descriptions
Directory traversal vulnerability in the GfdFileUploadServerlet servlet in Lexmark MarkVision Enterprise before 2.1 allows remote attackers to write to arbitrary files via unspecified vectors.
Una vulnerabilidad de salto de directorio en el servlet GfdFileUploadServerlet en Lexmark MarkVision Enterprise versiones anteriores a 2.1, permite a atacantes remotos escribir en archivos arbitrarios por medio de vectores no especificados.
This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Lexmark MarkVision Enterprise. Authentication is not required to exploit this vulnerability.
The specific flaw exists within the GfdFileUploadServlet class. The class contains a method that does not properly sanitize input allowing for directory traversal. An attacker can leverage this vulnerability to write files under the context of SYSTEM and achieve remote code execution.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2014-11-13 CVE Reserved
- 2014-12-09 CVE Published
- 2015-01-13 First Exploit
- 2024-08-06 CVE Updated
- 2024-10-27 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
CAPEC
References (4)
URL | Tag | Source |
---|---|---|
http://www.zerodayinitiative.com/advisories/ZDI-14-410 | Third Party Advisory | |
http://support.lexmark.com/index?page=content&id=TE666&locale=EN&userlocale=EN_US |
URL | Date | SRC |
---|---|---|
https://www.exploit-db.com/exploits/35776 | 2015-01-13 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
http://support.lexmark.com/index?page=content&id=TE666 | 2020-01-29 |
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Lexmark Search vendor "Lexmark" | Markvision Enterprise Search vendor "Lexmark" for product "Markvision Enterprise" | < 2.1 Search vendor "Lexmark" for product "Markvision Enterprise" and version " < 2.1" | - |
Affected
|