MEDIUM · 6.3

CVE-2024-2209

A user with administrative privileges can create a compromised dll file of the same name as the original dll within the HP printer’s Firmware Update Utility (FUU) bundle and place it in the Microsoft ...

Vulnerability Description

A user with administrative privileges can create a compromised dll file of the same name as the original dll within the HP printer’s Firmware Update Utility (FUU) bundle and place it in the Microsoft Windows default downloads directory which can lead to potential arbitrary code execution.

CVSS Score

6.3

MEDIUM

CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:L
Attack Vector
LOCAL
Attack Complexity
LOW
Privileges Required
HIGH
User Interaction
NONE
Scope
UNCHANGED
Confidentiality
HIGH
Integrity
HIGH
Availability
LOW

Affected Products

VendorProductVersions
Hp26K70B Firmware< 2349b
Hp26K70B-
Hp297X1A Firmware< 2349b
Hp297X1A-
Hp2A9Q5A Firmware< 2349b
Hp2A9Q5A-
Hp26K72A Firmware< 2349b
Hp26K72A-
Hp26K69A Firmware< 2349b
Hp26K69A-
Hp26K70A Firmware< 2349b
Hp26K70A-
Hp26K71A Firmware< 2349b
Hp26K71A-
Hp26K68A Firmware< 2349b
Hp26K68A-
Hp26K67A Firmware< 2349b
Hp26K67A-
Hp3Xv19A Firmware< 2349b
Hp3Xv19A-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2024-2209?

CVE-2024-2209 is a vulnerability with a CVSS score of 6.3 (MEDIUM). A user with administrative privileges can create a compromised dll file of the same name as the original dll within the HP printer’s Firmware Update Utility (FUU) bundle and place it in the Microsoft ...

How severe is CVE-2024-2209?

CVE-2024-2209 has been rated MEDIUM with a CVSS base score of 6.3/10. Review the CVSS metrics above for detailed severity breakdown.

Is there a patch for CVE-2024-2209?

Check the references section above for vendor advisories and patch information. Affected products include: Hp 26K70B Firmware, Hp 26K70B, Hp 297X1A Firmware, Hp 297X1A, Hp 2A9Q5A Firmware.