Canon Multifunction and Laser Printers Buffer Overflow Vulnerability Allowing Arbitrary Code Execution or Denial-of-Service

Vulnerability

A buffer overflow vulnerability has been identified in the TIFF data EXIF tag processing of certain Canon Small Office Multifunction Printers and Laser Printers. This vulnerability affects specific models sold in Japan, the US, and Europe, all running firmware through version 05.04. An attacker on the same network segment could exploit this vulnerability to cause the printer to become unresponsive or to execute arbitrary code.

Impact

Exploitation of this vulnerability could lead to arbitrary code execution or a denial-of-service condition, causing the printer to become unresponsive.

Remediation

Users are advised to update their printers to the latest firmware version. Instructions for downloading the firmware are available on the Canon support website. Additionally, it is recommended to use a firewall or router to create a secure private network for internet access, avoiding direct connections to the internet.

Added: Jun 9, 2025, 7:46 PM
Updated: Jun 9, 2025, 7:46 PM

Vulnerability Rating

Custom Algorithm
spread
5.7
impact
7.5
exploitability
7.0
remediation
7.9
relevance
0.0
threat
0.0
urgency
2.9
incentive
5.8

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.