CVE-2024-47177 is a rejected CVE candidate. It was assigned to command-execution behavior associated with the CUPS printing attack chain, but was determined to be fully interdependent with CVE-2024-47076, CVE-2024-47175, and CVE-2024-47176 and therefore does not identify a separate vulnerability. It must not be used for vulnerability tracking or remediation decisions.
Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.
What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.
What an attacker gets, and what they’ve been doing with it.
If you can’t patch tonight, do this now.
Patch, then assume compromise.
2 valid exploits after Mallory filtered fakes, detection scripts, and README-only repos (1 hidden).
Repository contains two distinct C++ utilities: a primary exploit (cups_rce_exploit.cpp with top-level README) and a defensive mitigation tool under Cups-Patcher/. The exploit is a standalone operational PoC for the September 2024 CUPS RCE chain. It implements a rogue TCP IPP server that listens on an attacker-specified IP/port, parses inbound IPP requests from cups-browsed, and returns crafted printer attributes. The key malicious behavior is injection of attacker-controlled content into the media-type-supported attribute, embedding a FoomaticRIPCommandLine directive and cupsFilter entry so the target eventually executes an arbitrary shell command via foomatic-rip. The exploit also supports optionally sending the initial UDP browse/discovery trigger to a target host on port 631, causing cups-browsed to connect back to the rogue IPP server. Payloads are user-supplied at runtime and may be passed directly or loaded from a file, making the exploit flexible but still basic rather than framework-grade. The repository structure is simple: 4 files total, with 2 code files and 2 README files. The main exploit entry point is cups_rce_exploit.cpp. The secondary tool, Cups-Patcher/cups_patcher.cpp, is not an exploit; it is a mitigation utility that disables cups-browsed, edits /etc/cups/cupsd.conf to disable browsing and bind to localhost, adds iptables/ip6tables rules blocking UDP 631, replaces foomatic-rip with a harmless stub, modifies /etc/hosts, creates backups, and supports restore/check/status style operations. This confirms the repository’s overall purpose is both offensive demonstration of the CUPS vulnerability chain and defensive hardening guidance. Notable network observables from the exploit include UDP 631 for the trigger, TCP 631 (or attacker-selected port) for the rogue IPP server, IPP URIs of the form ipp://ATTACKER:PORT/printers/NAME, and device URIs of the form socket://ATTACKER:PORT. Example payload observables in the README include reverse shell traffic to TCP 4444, file writes under /tmp, and retrieval of a second-stage script from http://192.168.1.50/backdoor.sh.
This repository contains a single Metasploit module: 'modules/exploits/multi/misc/cups_ipp_remote_code_execution.rb'. The module exploits several vulnerabilities in OpenPrinting CUPS and related components (cups-browsed, libcupsfilters, libppd, cups-filters) on Linux systems. It allows an attacker on the same LAN to advertise a malicious printer using mDNS (multicast DNS) to the address 224.0.0.251. When a victim sends a print job to this printer, the module delivers a payload via the IPP protocol, resulting in remote code execution as the 'lp' user on the victim's machine. The exploit does not require any open CUPS ports on the victim; only user interaction (sending a print job) is needed. The module references four CVEs (CVE-2024-47076, CVE-2024-47175, CVE-2024-47177, CVE-2024-47176) and is based on public research and exploits. The main attack vector is network-based, leveraging LAN multicast and HTTP/IPP services. The module is operational and allows for customizable payloads via the Metasploit framework.
Products and vendors Mallory has correlated with this vulnerability. Open in Mallory to drill down to specific CPE configurations and version ranges.
Vendor-confirmed product mapping. Mallory continuously reconciles this list against your asset inventory.
14 sources tracked across advisories, community write-ups, and news. New activity surfaces here as Mallory finds it.
Отклонённый как дубликат идентификатор, первоначально описывавший выполнение команд через foomatic-rip и директиву FoomaticRIPCommandLine в PPD-файле; в материале рассматривается как часть той же цепочки, но не как самостоятельная действующая CVE.
A CUPS command-execution flaw in which an injected FoomaticRIPCommandLine PPD parameter results in attacker-controlled command execution through the foomatic-rip filter when a print job is processed.
Critical vulnerability in cups-filters where the foomatic-rip print filter allows arbitrary command execution via FoomaticRIPCommandLine using attacker-controlled PPD values.
A vulnerability in cups-filters that is part of the disclosed CUPS/IPP malicious-printer and arbitrary-command-execution attack chain.
Query your assets running an affected version, and investigate the blast radius.
Every observed campaign linking this CVE to a named adversary.
Malware families riding this exploit, with evidence and IOCs.
YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.
Cross-references every affected SKU, including bundled OEM variants.
Community discussion across Reddit, Mastodon, and other social sources.