Vulnerabilities & PatchesEmerging2 srcs
CVE-2024-0244 – A heap buffer overflow in the Canon MF753Cdw printer
With Pwn2Own Ireland 2026 coming up, I wanted to share an unreleased blog post from my time as a Pwn2Own contestant. This post covers the discovery and exploitation of CVE-2024-0244, which is an unauthenticated heap-based buffer overflow leading to an arbitrary free() in the Canon MF753Cdw printer featured in Pwn2Own Toronto 2023.
This blog post gives an overview of the vulnerability and the exploitation techniques used.
Figure 1 - MF753Cdw printer
Figure 1 - MF753Cdw printer
Previously, I had exploited the very similarly named MF743Cdw at Pwn2Own Toronto 2022 using a classic stack buffer overflow, so I had a solid baseline understanding of this family of printers and their quirks. Starting Point Over the years at Pwn2Own, the Canon family of printers has been exploited many times, which means that many researchers have combed through the firmware.