← Terug naar overzicht

PaperCut has issued an urgent warning that threat actors are actively exploiting a zero-day vulnerability affecting all versions of its PaperCut NG and PaperCut MF print management software. The company has confirmed customer incidents and is treating the situation as its highest priority. An emergency patch has been released for versions 25 and 26 to address the vulnerability. The nature of the exploitation suggests organized and targeted attacks against PaperCut deployments. Organizations using any version of PaperCut NG or MF are urged to apply the emergency patch immediately to mitigate risk.

Technical details

A zero-day vulnerability is being actively exploited in all versions of PaperCut NG and PaperCut MF print management software. The exact nature of the flaw has not been publicly disclosed. Post-exploitation activity has been observed originating from the process 'pc-app.exe'. Attackers appear to be tampering with or deleting server log files to cover their tracks. Specific error entries in server.log are associated with exploitation activity. PaperCut has released an emergency patch for versions 25 and 26. The vulnerability appears to allow unauthorized access to the PaperCut Application Server, particularly when exposed to the internet. A historically similar critical flaw (CVE-2023-27350, CVSS 9.8) in PaperCut MF and NG was previously exploited to deliver Cl0p and LockBit ransomware.

Mitigation steps

1. Apply the emergency patch released for PaperCut NG/MF v25 and v26 immediately. 2. Restrict access to the PaperCut Application Server's web interfaces using firewall rules, network access controls, or equivalent measures to allow only trusted IP addresses. 3. Ensure the PaperCut server is not exposed to untrusted internet addresses. 4. Monitor intrusion-detection, endpoint-security, and network-monitoring tools for suspicious activity involving the PaperCut Application Server, particularly from 'pc-app.exe'. 5. Check server.log files for the identified IOC error entries and for missing or truncated logs. 6. Take network restriction actions immediately even if no suspicious activity has been observed.

Affected products

  • PaperCut MF (all versions)
  • PaperCut NG (all versions)

Related CVE's

  • CVE-2023-27350

Related threat actors

  • Lace Tempest
  • Russian threat actors

IOC's

Suspicious post-exploitation activity from process: pc-app.exe, Missing, unexpectedly truncated, or deleted PaperCut server.log files, server.log error entry: ERROR No suitable driver found for jdbc:no:x, server.log error entry: ERROR DatabaseUtils - Database error looking up cardID: VALUES CAST

Categories

  • Enterprise Applications
  • Ransomware & Malware
  • Zero-Day Vulnerabilities