Zero Day Initiative | Blog
Follow
CVE-2024-0244 – A heap buffer overflow in the Canon MF753Cdw printer
This post details the discovery and exploitation of CVE-2024-0244, a vulnerability in the Canon MF753Cdw printer. The researcher leveraged prior experience with Canon printers to investigate less obvious services. They focused on the fax driver, discovering that it sent SOAP messages to the printer. A malformed binary payload within these messages, specifically a large destination fax number, triggered a heap-based buffer overflow. This overflow led to an arbitrary free() vulnerability, where a controlled pointer was passed to the free() function. Exploiting this required a multi-step process involving the Canon proprietary BJNP protocol. First, fake heap chunks were placed at known addresses using BJNP. Then, shellcode was uploaded to another known BJNP address. The arbitrary free was triggered, placing a fake BJNP chunk onto the free list. A subsequent heap allocation reused this chunk. Finally, this reused chunk was overwritten through another BJNP session to redirect a function pointer to the uploaded shellcode. This allowed for arbitrary code execution, demonstrated by displaying DOOM on the printer's screen. The post concludes by acknowledging the evolving security of Canon printers and anticipates future research for Pwn2Own Ireland 2026.