A four-CVE chain affecting CUPS and its cups-browsed component allows unauthenticated attackers to trigger remote command execution on vulnerable Linux systems, with potential exposure for macOS hosts using CUPS. An attacker can send a crafted UDP packet to port 631, induce cups-browsed to retrieve data from an attacker-controlled IPP server, and inject malicious printer attributes into a temporary PPD file; execution occurs when a user submits a print job.
The resulting commands run as the lp user and may be constrained by the cupsd AppArmor profile. Internet-exposed CUPS services face the highest risk. Security teams should investigate unexpected UDP/631 traffic, untrusted or anomalous lp-owned files, foomatic-rip executions, and known proof-of-concept marker files; the attack was publicly disclosed with an RCE proof of concept before CVEs and patches were broadly available.

See affected versions and whether adversaries are exploiting it.
5 events from the most recent confirmed update back to the earliest known activity.
Wiz Threat Research and Datadog observed several IP addresses scanning or communicating with UDP port 631 following disclosure of the CUPS flaw chain. Wiz stated that no successful in-the-wild exploitation had been reported as of September 29, though the activity could represent malicious scanning or security research.
Simone Margaritelli, known as EvilSocket, publicly disclosed the CUPS remote-code-execution chain and an RCE proof of concept. Exploitation begins with an unauthenticated UDP/631 request to cups-browsed and requires a user to submit a print job to trigger the injected command.
The CUPS/cups-browsed vulnerability chain was initially reported to maintainers. The chain includes flaws later tracked as CVE-2024-47176, CVE-2024-47076, CVE-2024-47175, and CVE-2024-47177.
Elastic released out-of-the-box detection-rule updates for supported Stack versions to identify possible CUPS exploitation, including suspicious shell execution, outbound connections, and file creation by foomatic-rip or its lp-owned child processes.
Vulnerability details were reportedly leaked before CVE assignments and patches were available, preceding the public disclosure.
Vulnerabilities, threat actors, malware, products, organizations, breaches, and observables Mallory has linked to this story. Indicator values are masked here and available in full in the app.
Indicator values are masked on this page. See the values in Mallory Domains, IPs, hashes, and URLs are exportable to your SIEM.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
4 references tracked. Mallory keeps watching after this page renders.
oligo.security
Open sourcewiz.io
Open sourceelastic.co
Open sourceevilsocket.net
Open sourceMap indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.