Security Updates: Attackers can push malicious code onto Lexmark printers
Three security vulnerabilities threaten various Lexmark printer models – one is classified as critical.
Malicious code can slip onto certain Lexmark printers via three vulnerabilities, compromising them. The developers have now resolved the security issues with updates.
Lexmark has published security alerts for the vulnerabilities (CVE-2025-65083 “critical,” CVE-2025-65079 “medium,” CVE-2025-65081 “medium”). The list of specifically threatened models is too extensive for this report. It includes laser printers such as the MX432 and C4342. Admins can find the complete list in the security alerts.
In all cases, attackers can execute malicious code remotely. The Embedded Solutions Framework and the Postscript interpreter are potential entry points. More detailed information on how possible attacks might unfold is not currently available. So far, Lexmark has no indications of ongoing attacks.
Videos by heise
To prevent potential attacks, administrators must install the security patches listed in the security alerts linked above.
(des)