Critical PaperCut NG/MF Vulnerability Exploited in Active Attacks
Unknown PaperCut NG/MF vulnerability is under active exploitation, according to a security advisory from the software provider.
Overview of PaperCut NG/MF
PaperCut NG is print management software for offices and educational institutions, while PaperCut MF (Multi-Function) integrates with multifunctional devices for printing, copying, scanning, and faxing. Both systems are embedded in device touchscreens and support copiers from major manufacturers.
Security Advisory Details
A previously unidentified vulnerability in PaperCut NG/MF is being actively exploited by malicious actors. The flaw allows remote exploitation, and organizations with PaperCut NG/MF Application Servers exposed to the public internet are urged to restrict web access to trusted IP addresses immediately.
Key Features of PaperCut NG and MF
PaperCut NG focuses on managing print processes from computer and server endpoints, while PaperCut MF connects directly to hardware for enhanced security and additional capabilities. The Application Server acts as the central component for both systems and is typically deployed once per organization.
According to the software provider, confirmed instances of attacks have been reported, emphasizing the urgency of addressing the issue.
Indicators of Compromise and Mitigation
Organizations are advised to monitor for alerts from security tools related to the PaperCut Application Server, particularly suspicious post-exploitation behavior linked to pc-app.exe. Signs to watch for include missing, altered, or deleted server.log files, as well as specific error messages in the log files such as "ERROR No suitable driver found for jdbc:no:x" or "ERROR DatabaseUtils Database error looking up cardID: VALUES CAST."
Even without these indicators, strict access controls must be enforced. Measures such as firewall configurations, network segmentation, or similar protocols should prevent external access to the PaperCut server’s web interfaces.
Historical Context and Proactive Measures
This follows prior incidents where ransomware groups like Clop and LockBit exploited known vulnerabilities in the same software. In 2023, threat actors leveraged CVE-2023-27350 and CVE-2023-27351 to achieve remote code execution and data exposure.
The advisory underscores the importance of proactive security measures and timely response to emerging threats. Organizations using PaperCut solutions are encouraged to review their configurations and implement recommended safeguards immediately.
