Aug. 10, 2023, 8:41 p.m. | James Horseman

Security Boulevard securityboulevard.com

Introduction In December 2022, we competed at our first pwn2own. We were able to successfully exploit the Lexmark MC3224i using a command injection 0-day. This post will detail the process we used to discover, weaponize, and have some fun with this vulnerability. You can find our POC here. Printer Acquisition It was rather difficult to […]


The post Lexmark Command Injection Vulnerability ZDI-CAN-19470 Pwn2Own Toronto 2022 appeared first on Horizon3.ai.


The post Lexmark Command Injection Vulnerability ZDI-CAN-19470 Pwn2Own Toronto …

acquisition blog command command injection december discover exploit find fun injection introduction lexmark poc printer process pwn2own pwn2own toronto 2022 red team social engineering toronto vulnerability zdi

Red Team Operator

@ JPMorgan Chase & Co. | LONDON, United Kingdom

SOC Analyst

@ Resillion | Bengaluru, India

Director of Cyber Security

@ Revinate | San Francisco Bay Area

Jr. Security Incident Response Analyst

@ Kaseya | Miami, Florida, United States

Infrastructure Vulnerability Consultant - (Cloud Security , CSPM)

@ Blue Yonder | Hyderabad

Product Security Lead

@ Lely | Maassluis, Netherlands