lexmark printer haxx
I made an entry for Pwn2Own Toronto 2022, that magically failed during the actual competition. ZDI offered to buy the bug(s) anyway for a laughable monetary amount and I promptly forgot about their offer.
Here is a small archive with exploit, writeup and tools.
Exploit was tested against the Lexmark 'MC3224adwe' but is reported to work against other printers/copiers as well. ;-)
This is all still "0day" at the time of writing (2023-01-10, tested against firmware CXLBL.081.225)
Everything is distributed as-is, don't expect support/updates.
Enjoy!
-- blasty [email protected]