CVE-2021-38085

HIGH

Canon TR150 <3.71.2.10 - Privilege Escalation

Title source: llm
STIX 2.1

Exploitation Summary

EIP tracks 1 public exploit for CVE-2021-38085. PoCs published by Jacob Baines, Shelby Pace, including Metasploit module exploits/windows/local/canon_driver_privesc.

AI-analyzed exploit summary This Metasploit module exploits a DLL hijacking vulnerability in Canon TR150 printer drivers (CVE-2021-38085) to achieve local privilege escalation to NT AUTHORITY\SYSTEM by overwriting a DLL in a writable directory and triggering its execution via the PrintIsolationHost.exe process.

Description

The Canon TR150 print driver through 3.71.2.10 is vulnerable to a privilege escalation issue. During the add printer process, a local attacker can overwrite CNMurGE.dll and, if timed properly, the overwritten DLL will be loaded into a SYSTEM process resulting in escalation of privileges. This occurs because the driver drops a world-writable DLL into a CanonBJ %PROGRAMDATA% location that gets loaded by printisolationhost (a system process).

Exploits (1)

metasploit WORKING POC NORMAL
by Jacob Baines, Shelby Pace · rubypocwin
https://github.com/rapid7/metasploit-framework/blob/master/modules/exploits/windows/local/canon_driver_privesc.rb

This Metasploit module exploits a DLL hijacking vulnerability in Canon TR150 printer drivers (CVE-2021-38085) to achieve local privilege escalation to NT AUTHORITY\SYSTEM by overwriting a DLL in a writable directory and triggering its execution via the PrintIsolationHost.exe process.

Classification
Working Poc 100%
Attack Type
Lpe
Complexity
Moderate
Reliability
Racy
Target: Canon TR150 print drivers versions 3.71.2.10 and below
Auth required
Prerequisites: Local access to the target system · Canon TR150 printer driver installed · Ability to execute commands as a non-privileged user
devstral-2 · analyzed Feb 16, 2026 Full analysis →

References (4)

Core 4
Core References
Third Party Advisory x_refsource_misc
https://defcon.org/html/defcon-29/dc-29-speakers.html#baines
Exploit, Third Party Advisory x_refsource_misc
https://www.youtube.com/watch?v=vdesswZYz-8

Scores

CVSS v3 7.8
EPSS 0.0101
EPSS Percentile 58.5%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-732
Status published
Products (1)
canon/pixma_tr150_firmware < 3.71.2.10
Published Aug 11, 2021
Tracked Since Feb 18, 2026