
Python PoC reproducing the CUPS 2.4.16 local-printer flaw: captures the Local auth token via a rogue IPP endpoint, creates a file:// printer, and races a job to write root-owned files.
Authorized testing / research use only. Run this PoC only against systems you own or are explicitly authorized to test.
This repository contains a system-CUPS-oriented reproduction of the local-printer vulnerability in CUPS 2.4.16.
The implementation was developed from the published CUPS vulnerability reproduction and adapted to work against an already-running system CUPS installation, rather than requiring a separately installed CUPS build and a root-run reproduction harness.
The reproduction follows this general chain:
CUPS 2.4.16
│
▼
Local authentication challenge
│
▼
Attacker-controlled IPP endpoint
│
▼
Authorization: Local <token>
│
▼
Authenticated CUPS administration
│
▼
CUPS-Create-Local-Printer
│
▼
file:// device URI
│
▼
Printer/job race
│
▼
Root-owned target file
The exploit is race-dependent, so successful execution is not guaranteed on every attempt.
The published reproduction is designed as a controlled vulnerability harness. In particular, it assumes a dedicated CUPS installation and performs setup/reset operations that are appropriate for a reproduction environment but are not representative of an already-running distribution installation.
This implementation instead:
ipptool binary.cups-create-local-printer.test definition when available.Local authorization token.file:// primitive.Tested in the author's lab with:
ipptoolThe test definition is expected at:
/usr/share/cups/ipptool/cups-create-local-printer.test
Check your installation with:
cupsd -v
which ipptool
find /usr/share/cups -name 'cups-create-local-printer.test' 2>/dev/null
Configure the attacker identity and target path through environment variables:
export CUPS_ATTACKER="$USER"
export CUPS_TARGET="/tmp/cups-poc-target"
python3 exploit.py
For a controlled privilege-escalation reproduction, choose a target appropriate to your isolated test environment.
The script also defaults to a sudoers-style target under /etc/sudoers.d/, so do not run it casually on a production system.
The PoC starts an IPP listener and causes CUPS to authenticate against it. The listener initially returns a 401 challenge with:
WWW-Authenticate: Local trc="y"
The subsequent request contains:
Authorization: Local <token>
The token is then reused against the local CUPS administration endpoint.
The reproduction uses:
CUPS-Create-Local-Printer
with a file:// device URI.
The candidate loop performs the printer operations repeatedly, including:
CUPS-Add-Modify-Printer
CUPS-Accept-Jobs
Resume-Printer
Print-Job
The race is intentionally repeated because a single attempt may not win.
This repository is an adaptation, not the canonical upstream implementation.
The request-building logic and exploitation sequence are based on the published reproduction. The main changes are around running against an existing system CUPS installation and removing reproduction-environment setup/reset assumptions.
See the upstream OpenPrinting CUPS security advisory and repository for the authoritative vulnerability information and original reproduction.
Do not use this against CUPS installations without authorization.
For defensive validation, the useful indicators include unexpected IPP requests to attacker-controlled endpoints, unusual Local authentication exchanges, creation of unexpected local printers, and suspicious printer/job activity.