Millions of HP, Samsung, and Xerox Printers Vulnerable Due to 16-Year-Old Security Flaw
July 20, 2021
A serious security vulnerability has come to light in a software driver used by HP, Xerox, and Samsung printers, lingering undetected since 2005. Assigned CVE-2021-3438 (CVSS score: 8.8), this issue involves a buffer overflow in the “SSPORT.SYS” print driver installer, which could allow for remote privilege escalation and arbitrary code execution. Hundreds of millions of printers worldwide may be affected, although there is currently no evidence of real-world exploitation. The vulnerability, first identified by SentinelLabs researchers on February 18, 2021, was disclosed in an advisory in May, noting its potential to elevate privileges in certain HP LaserJet and Samsung printer models. Fixes for the impacted devices were made available on May 19, 2021.
Longstanding Security Flaw in Printer Software Puts Millions at Risk On July 20, 2021, cybersecurity experts disclosed a critical vulnerability that has affected millions of printers globally. This issue stems from a software driver utilized by HP, Xerox, and Samsung…