CVE-2025-65078Disclosure

LOWCVSS 9.3 · CRITICAL

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft
  • Track advisory updates for patch or workaround availability

Recommended action window: High priority (within 72h)

NVD description

An untrusted search path vulnerability has been identified in the Embedded Solutions Framework in various Lexmark devices. This vulnerability can be leveraged by an attacker to execute arbitrary code.

1.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-426

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

STABLE

Threat summary

  • Public PoC is present in monitored signal
  • 3 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 1 signal
  • Technical details provided in 3 signals
  • Disclosure: 3 classified signals
  • Peaked 1d ago at 2 mentions (2026-02-03); latest day: 1
  • 3 total mentions across 2 days

Deep dive

Activity timeline3 mentions / 2d
01122Mentions · 2026-02-03: 2Mentions · 2026-02-12: 1PoC Mentioned / Linked · 2026-02-03: 1Technical Details · 2026-02-03: 2Technical Details · 2026-02-12: 102-0302-12
Signal classification1 categories
Disclosure
3100.0%
Referenced assets3 URLs
Classification over time
DateTotalLabels
2026-02-032
Disclosure2
2026-02-121
Disclosure1
Full discourse3 posts
  • TheZDIBugs@TheZDIBugs
    Disclosure

    [ZDI-26-062|CVE-2025-65078] (Pwn2Own) Lexmark CX532adwe esfhelper Untrusted Search Path Local Privilege Escalation Vulnerability (CVSS 7.8; Credit: Interrupt Labs) https://www.zerodayinitiative.com/advisories/ZDI-26-062/

    Post summary

    A new local privilege escalation vulnerability (CVE‑2025‑65078) in Lexmark CX532adwe eshelper is disclosed with a CVSS score of 7.8, and a reference to a Zeroday advisory is provided.

    00022668
    5.3K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2025-65078 An untrusted search path vulnerability has been identified in the Embedded Solutions Framework in various Lexmark devices. This vulnerability can be leveraged by an a… https://www.cve.org/CVERecord?id=CVE-2025-65078

    Post summary

    An untrusted search path vulnerability in Lexmark Embedded Solutions Framework has been reported; no PoC, exploit, or active usage is mentioned, and no patch information is provided.

    00000173
    56.5K followersView on X
  • 0day Signal@0dayPublishing
    Disclosure

    🚨 CVE-2025-65078: Untrusted search path vulnerabil... Lexmark's untrusted search path flaw (CVE-2025-65078) enables DLL hijacking with zero user interaction - trivial remote... https://zerodaysignal.com/vulnerability/CVE-2025-65078 #netsec #vulnerability #CVE #sysadmin #zeroday

    Post summary

    The post announces the discovery of CVE-2025-65078, an untrusted search path flaw in Lexmark that permits DLL hijacking with zero user interaction, and provides a link to a vulnerability page without detailing an exploit or patch.

    0000043
    132 followersView on X

Explore more