CVE-2021-38085

HIGH

Canon TR150 <3.71.2.10 - Privilege Escalation

Title source: llm
STIX 2.1

Description

The Canon TR150 print driver through 3.71.2.10 is vulnerable to a privilege escalation issue. During the add printer process, a local attacker can overwrite CNMurGE.dll and, if timed properly, the overwritten DLL will be loaded into a SYSTEM process resulting in escalation of privileges. This occurs because the driver drops a world-writable DLL into a CanonBJ %PROGRAMDATA% location that gets loaded by printisolationhost (a system process).

Exploits (1)

metasploit WORKING POC NORMAL
by Jacob Baines, Shelby Pace · rubypocwin
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/windows/local/canon_driver_privesc.rb

Scores

CVSS v3 7.8
EPSS 0.0367
EPSS Percentile 87.9%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-732
Status published
Products (1)
canon/pixma_tr150_firmware < 3.71.2.10
Published Aug 11, 2021
Tracked Since Feb 18, 2026