Cyber News / Article / CVE-2024-47076, CVE-2024-47175, CVE-2024-47176, CVE-2024-47177: Everything you need to know

CVE-2024-47076, CVE-2024-47175, CVE-2024-47176, CVE-2024-47177: Everything you need to know
Detect and mitigate CVE-2024-47076, CVE-2024-47175, CVE-2024-47176, and CVE-2024-47177 vulnerabilities impacting CUPS and IPP packages.
The security researcher Simone Margaritelli (evilsocket), disclosed details of several vulnerabilities impacting CUPS and IPP packages: CVE-2024-47176, CVE-2024-47076, CVE-2024-47175, and CVE-2024-47177. These vulnerabilities are unlikely to be exploited in most cloud environments due to their requirements for exposing UDP port 631 and needing the victim to attempt a print request as part of the currently disclosed exploitation method.
The vulnerabilities received CVSS base scores ranging from 8.0 to 9.0. It is recommended to mitigate these vulnerabilities and apply patches.
A remote, unauthenticated attacker can replace existing printers with a malicious one or add a new printer under their control, leading to arbitrary command execution when a print job is initiated from the affected system. The attack begins by sending a UDP packet to port 631, or in local LANs, attackers may spoof DNS advertisements. On vulnerable systems, the attacker can exploit this to replace or install a printer configuration on the victim's system that points to the attacker’s system. As part of the print service, an installed printer has the ability to execute arbitrary commands on the requesting system when a print request is made to it. In the most common scenarios the commands are run by the `lp` user, which is unprivileged.
According to Wiz data, 83% of cloud environments have at least one instance of the affected packages in the vulnerable version ranges. However, considering the current known exploitation method, we estimate that cloud environments are highly unlikely to be exploited remotely, since printing devices are rarely used in the cloud, and UDP port 631 is rarely open.
While no successful exploitation has been reported in the wild as of today, September 29, 2024, Wiz Threat Research has observed the following IPs attempting UDP communication through port 631, most likely scanning this port for malicious purposes or as part of security research -
195.228.75[.]121,143.244.47[.]70,172.234.96[.]249and172.234.96[.]249have also been observed byDataDog.
The following table lists the vulnerabilities and their impacted products:
Few vendors released patches, it is also possible to apply these mitigations:
Avoid exposing UDP port 631 and stop/disablecups-browsed.
If CUPS support is required, you can applythis mitigation:
Edit/etc/cups/cups-browsed.conf
Search for theBrowseRemoteProtocolsconfiguration option
Set the option todnssd(the default value isdnssd cups, removecups)
Restartcups-browsedusingsudo systemctl restart cups-browsed
Wiz customers can use the pre-built query and advisory in theWiz Threat Centerto search for vulnerable instances in their environment.
Vulnerability writeup by evilsocket
Redhat blog
Ubuntu advisory
GHSA for cups-browsed
GHSA for cups-filters
GHSA for libcupsfilters
GHSA for libppd
Critical severity vulnerability CVE-2024-0132 affecting NVIDIA Container Toolkit and GPU Operator presents high risk to AI workloads and environments.
Enhance your security with Wiz’s new hybrid File Integrity Monitoring (FIM) solution, combining agentless and runtime capabilities for comprehensive file monitoring.
Gain unified visibility into Snowflake security posture and threats with the same workflows as the rest of your cloud.
Get a personalized demo
©2026Wiz, Inc.
StatusPrivacy PolicyTerms of UseModern Slavery StatementCookie Settings
Related articles
Introducing Unit 42 Threat Intelligence: Know What Matters, Understand the Adversary, and Act Faster
2026-08-03
See and Secure Everything at the Edge with Wiz and Akamai
2026-05-08
Trivy Compromised: Everything You Need to Know about the Latest Supply Chain Attack
2026-03-20
You might Also like

Windows BitLocker Vulnerability Allows Attackers to Execute Malicious Code Remotely

Man gets 15 years for extorting women with AI-generated porn videos

