PaperCut has issued a warning regarding active zero-day exploitation of a vulnerability affecting all versions of its PaperCut NG and PaperCut MF print management software. The flaw is being leveraged by hackers in ongoing attacks, making it a critical threat to organizations using these products. PaperCut NG and MF are widely deployed in enterprise and educational environments for print management. The zero-day nature of the attacks means no patch was available at the time of initial exploitation. Organizations using these products are urged to apply any available mitigations or patches immediately. The vulnerability's broad scope, affecting all versions, significantly increases the attack surface.
A zero-day vulnerability affects all versions of PaperCut NG and PaperCut MF print management software. PaperCut has not publicly disclosed the full technical details of the flaw or exact exploitation method. The vulnerability was reproduced by PaperCut's security team using information provided by a University customer. Confirmed customer incidents have been reported. Suspicious activity has been observed from the legitimate PaperCut pc-app.exe process. Server log files (server.log) have been found modified, deleted, or missing on compromised systems. Two specific error messages in server.log indicate potential compromise: 'ERROR No suitable driver found for jdbc:no:x' and 'ERROR DatabaseUtils - Database error looking up cardID: VALUES CAST'. Emergency patches have been released for customers with public-facing PaperCut NG/MF servers. In a historical parallel, CVE-2023-27350 was a critical unauthenticated authentication bypass and remote code execution vulnerability previously exploited by multiple threat actors including Clop, LockBit, Iranian state-backed groups, and Bl00dy Ransomware Gang.
1. Apply the emergency patches released by PaperCut immediately, especially for public-facing PaperCut NG/MF servers. 2. If patching is not immediately possible, use firewall rules or network access controls to restrict the PaperCut Application Server web interface to trusted IP addresses only. 3. Ensure Internet-exposed PaperCut Application Servers are not publicly accessible. 4. Review server.log files for the following error indicators: 'ERROR No suitable driver found for jdbc:no:x' and 'ERROR DatabaseUtils - Database error looking up cardID: VALUES CAST'. 5. Monitor for suspicious activity originating from the pc-app.exe process. 6. Check if server.log files have been modified, deleted, or are missing. 7. Note that absence of indicators of compromise does not confirm the server has not been compromised. 8. Monitor PaperCut's security advisory for updated indicators of compromise and additional remediation guidance.
Suspicious activity from legitimate PaperCut process: pc-app.exe, server.log files that have been modified, deleted, or are missing, ERROR log entry: 'No suitable driver found for jdbc:no:x', ERROR log entry: 'DatabaseUtils - Database error looking up cardID: VALUES CAST'