CVE-2024-47176 is an origin-validation flaw in CUPS cups-browsed versions through 2.0.1. The service binds UDP port 631 on all interfaces and accepts discovery packets without validating their source, allowing an unauthenticated attacker to cause a Get-Printer-Attributes IPP request to an attacker-controlled URL. In combination with related CUPS attribute-validation and print-filter vulnerabilities, attacker-controlled printer configuration can lead to command execution when a print job is submitted.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
5 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos (9 hidden).
Repository contains two distinct C++ utilities: a primary exploit (cups_rce_exploit.cpp with top-level README) and a defensive mitigation tool under Cups-Patcher/. The exploit is a standalone operational PoC for the September 2024 CUPS RCE chain. It implements a rogue TCP IPP server that listens on an attacker-specified IP/port, parses inbound IPP requests from cups-browsed, and returns crafted printer attributes. The key malicious behavior is injection of attacker-controlled content into the media-type-supported attribute, embedding a FoomaticRIPCommandLine directive and cupsFilter entry so the target eventually executes an arbitrary shell command via foomatic-rip. The exploit also supports optionally sending the initial UDP browse/discovery trigger to a target host on port 631, causing cups-browsed to connect back to the rogue IPP server. Payloads are user-supplied at runtime and may be passed directly or loaded from a file, making the exploit flexible but still basic rather than framework-grade. The repository structure is simple: 4 files total, with 2 code files and 2 README files. The main exploit entry point is cups_rce_exploit.cpp. The secondary tool, Cups-Patcher/cups_patcher.cpp, is not an exploit; it is a mitigation utility that disables cups-browsed, edits /etc/cups/cupsd.conf to disable browsing and bind to localhost, adds iptables/ip6tables rules blocking UDP 631, replaces foomatic-rip with a harmless stub, modifies /etc/hosts, creates backups, and supports restore/check/status style operations. This confirms the repository’s overall purpose is both offensive demonstration of the CUPS vulnerability chain and defensive hardening guidance. Notable network observables from the exploit include UDP 631 for the trigger, TCP 631 (or attacker-selected port) for the rogue IPP server, IPP URIs of the form ipp://ATTACKER:PORT/printers/NAME, and device URIs of the form socket://ATTACKER:PORT. Example payload observables in the README include reverse shell traffic to TCP 4444, file writes under /tmp, and retrieval of a second-stage script from http://192.168.1.50/backdoor.sh.
This repository contains a single standalone Python exploit script, main.py, targeting CUPS and explicitly labeled for CVE-2024-47176. The script is not part of a larger framework. Its structure is simple but fully operational: it combines an attacker-hosted Flask web server, UDP trigger logic, malicious PPD generation, and a TCP reverse-shell listener into one file. Core exploit flow: (1) the script builds a malicious PPD containing a FoomaticRIPCommandLine directive; (2) that directive embeds a Python3 reverse shell one-liner that connects back to the attacker and launches /bin/sh -i; (3) a Flask app serves this PPD content to any incoming path, acting as the attacker-controlled IPP/HTTP endpoint; (4) the script sends crafted UDP packets to the target on port 631 to advertise or trigger use of the attacker-controlled printer URI; and (5) once the target processes the malicious printer definition and a print job is triggered, the reverse shell connects back to the attacker listener. Notable functions: ipp_handler() logs inbound requests and returns the malicious PPD; start_ipp_server() launches the Flask server; send_udp_trigger() sends two UDP payload variants to the target, one containing an ipp:// URI and another containing an http://.../printer URI; start_shell_listener() waits for the reverse shell and provides an interactive command loop; main() parses arguments, constructs the payload, starts the server/listener threads, sends the trigger, and prints operator instructions. The exploit’s main capability is remote code execution leading to an interactive reverse shell, contingent on the target CUPS environment accepting and executing the malicious PPD/foomatic-rip command path. The repository contains no detection-only logic, no obfuscation, and no additional modules or support files.
This repository contains a single Metasploit module: 'modules/exploits/multi/misc/cups_ipp_remote_code_execution.rb'. The module exploits several vulnerabilities in OpenPrinting CUPS and related components (cups-browsed, libcupsfilters, libppd, cups-filters) on Linux systems. It allows an attacker on the same LAN to advertise a malicious printer using mDNS (multicast DNS) to the address 224.0.0.251. When a victim sends a print job to this printer, the module delivers a payload via the IPP protocol, resulting in remote code execution as the 'lp' user on the victim's machine. The exploit does not require any open CUPS ports on the victim; only user interaction (sending a print job) is needed. The module references four CVEs (CVE-2024-47076, CVE-2024-47175, CVE-2024-47177, CVE-2024-47176) and is based on public research and exploits. The main attack vector is network-based, leveraging LAN multicast and HTTP/IPP services. The module is operational and allows for customizable payloads via the Metasploit framework.
This repository provides a functional proof-of-concept (PoC) exploit for CVE-2024-47176, a critical unauthenticated remote code execution vulnerability in the cups-browsed service (version 2.0.1 and below) on GNU/Linux systems. The exploit is implemented in a single Python script (CVE-2024-47176.py) and leverages the ability of cups-browsed to auto-discover and trust network printers via IPP (Internet Printing Protocol) on port 631. The script sets up a malicious IPP printer server and advertises it on the network using Zeroconf/mDNS. When a vulnerable cups-browsed client discovers and interacts with this fake printer, the exploit can inject arbitrary commands (such as a reverse shell) into the printer's configuration, which are then executed on the target system. The payload can be provided as a direct command or as a file (e.g., rev.sh). The exploit requires the attacker to have network access to the target and for the target to attempt to print to the attacker's malicious printer. The repository also includes a detailed README with vulnerability background, usage instructions, and references. No detection scripts or fake code are present; the code is a real exploit with operational payload capability.
This repository contains an operational exploit for CVE-2024-47176, a remote command execution vulnerability in the CUPS (Common UNIX Printing System) cups-browsed component. The exploit consists of a Python script ('evilcups.py') and a README.md with usage instructions. The script sets up a malicious IPP (Internet Printing Protocol) server on the attacker's machine and sends a specially crafted UDP packet to the target's port 631 (IPP). This packet advertises the attacker's server as a printer, and when the target CUPS server connects back to retrieve printer attributes, the exploit delivers a payload via the 'printer-more-info' attribute, which can result in arbitrary command execution on the target. The attacker can supply any command, such as a reverse shell, to gain remote access. The exploit requires the target's port 631 to be accessible and the cups-browsed functionality to be enabled. The repository is well-structured, with clear instructions and a single Python exploit script as the main entry point.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
17 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
A vulnerability tracked as CVE-2024-47176, covered by an AlmaLinux 9.2 local security-check plugin and rated Important by the vendor.
Unknown
A specific vulnerability identified as CVE-2024-47176, referenced here as something SpooNMAP can detect in cups-browsed.
Уязвимость в cups-browsed, позволяющая неаутентифицированному удалённому атакующему через UDP 631 заставить сервис обратиться к атакующему IPP-серверу и зарегистрировать подставной принтер как часть цепочки к RCE.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.