Intrusion Prevention

Xerox.Multifunction.Printers.Remote.Code.Execution

Description

This indicates an attack attempt to exploit a Code Injection Vulnerability in Xerox Multifunction printers.
The vulnerability is due to an input validation error while parsing a crafted Dynamic Loadable Module. A remote attacker could exploit this to execute arbitrary code within the context of the application, via a crafted Dynamic Loadable Module.

Affected Products

Xerox Multifunction printers.

Impact

System Compromise: Remote attackers can gain control of vulnerable systems.

Recommended Actions

Apply the most recent upgrade or patch from the vendor.
http://www.xerox.com/download/security/security-bulletin/1284332-2ddc5-4baa79b70ac40/cert_XRX12-003_v1.1.pdf