CVE-2025-65079Disclosure

LOWCVSS 6.9 · MEDIUM

Exploit discussion active in current signal (1 latest mentions)

Immediate actions

  • Hunt for exploitation attempts and persistence artifacts
  • Increase monitoring for publicly documented tradecraft
  • Track advisory updates for patch or workaround availability

Recommended action window: High priority (within 72h)

NVD description

A heap-based buffer overflow vulnerability has been identified in the Postscript interpreter in various Lexmark devices. This vulnerability can be leveraged by an attacker to execute arbitrary code as an unprivileged user.

1.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-122

Priority

LOW

Exploitation

NONE

PoC

YES

Patch

NONE

Momentum

STABLE

Threat summary

  • Public PoC is present in monitored signal
  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • PoC mentioned or linked in 1 signal
  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • Peaked 1d ago at 1 mentions (2026-02-03); latest day: 1
  • 2 total mentions across 2 days

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-02-03: 1Mentions · 2026-02-12: 1PoC Mentioned / Linked · 2026-02-12: 1Technical Details · 2026-02-03: 1Technical Details · 2026-02-12: 102-0302-12
Signal classification1 categories
Disclosure
2100.0%
Referenced assets2 URLs
Full discourse2 posts
  • TheZDIBugs@TheZDIBugs
    Disclosure

    [ZDI-26-066|CVE-2025-65079] (Pwn2Own) Lexmark CX532adwe getCFFNames Heap-based Buffer Overflow Remote Code Execution Vulnerability (CVSS 8.8; Credit: Team ANHTUD) https://www.zerodayinitiative.com/advisories/ZDI-26-066/

    Post summary

    Lexmark CX532adwe is disclosed as having a heap-based buffer overflow that allows remote code execution (CVSS 8.8), announced by ZDI with a Pwn2Own demonstration, and no patch is mentioned.

    00032721
    5.3K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2025-65079 A heap-based buffer overflow vulnerability has been identified in the Postscript interpreter in various Lexmark devices. This vulnerability can be leveraged by an att… https://www.cve.org/CVERecord?id=CVE-2025-65079

    Post summary

    A heap‑based buffer overflow was identified in the Postscript interpreter on Lexmark devices (CVE‑2025‑65079). No PoC, exploit code, active exploitation, patch, or debunking claim is mentioned.

    00010194
    56.5K followersView on X

Explore more