PaperCut Issues Critical Security Update to Fix Exploited Zero-Day Vulnerability

www.news4hackers.com-papercut-issues-critical-security-update-to-fix-exploited-zero-day-vulnerability-papercut-issues-critical-security-update-to-fix-exploited-zero-day-vulnerability

PaperCut Software is alerting users of its NG and MF print management systems about an actively exploited zero-day vulnerability.

Urgent Patch Released for Zero-Day Vulnerability

The flaw remains unassigned a CVE identifier, with no technical specifics disclosed publicly. The vendor issued urgent patches on Friday and advised customers to apply them immediately.

Details of the Vulnerability

PaperCut recommends isolating the application server from the internet and limiting access to verified IP addresses. “We have confirmed incidents involving customers and are addressing this issue with the utmost urgency. Our investigation is ongoing,” the company stated in its advisory.

The perpetrator behind the exploitation remains unidentified. PaperCut has provided indicators of compromise, including the presence of a suspicious file named pc-app.exe, which suggests the deployment of malware or post-exploitation tools. The company also highlighted that server.log files being unexpectedly truncated or deleted could signal an intrusion. Alterations or removal of log files may indicate adversaries attempting to erase evidence of their activities.

Customer Impact and Response

This marks the second instance where a PaperCut NG/MF vulnerability has been exploited in the wild. CISA’s Known Exploited Vulnerabilities (KEV) catalog lists three flaws, though this latest issue has not been included. Two of the KEV-listed vulnerabilities have been linked to ransomware attacks.

Global Exposure and Risk

According to data from the ShadowServer Foundation, approximately 1,000 PaperCut installations are currently accessible via the internet, with the majority located in North America and Europe.



About Author

en_USEnglish