PaperCut Zero-Day Exploited in Attacks, Affecting All NG and MF Versions
PaperCut has confirmed a zero-day vulnerability is being actively exploited in its print management software, impacting all versions of NG and MF. The company released a patch and urges users to restrict internet access to their servers to prevent further attacks, following a previous exploitation in 2023 by Russian threat actors and the Lace Tempest group.
PaperCut has issued an alert to its customers regarding a critical zero-day vulnerability being exploited in its PaperCut NG and PaperCut MF print management software. The vulnerability is affecting all versions of the software, and the company has released an emergency patch to address the issue. They are currently investigating confirmed customer incidents and treating the matter with the highest priority.
So far, indicators of compromise include alerts from intrusion-detection, endpoint-security, or network-monitoring tools showing suspicious post-exploitation activity from "pc-app.exe", as well as missing, unexpectedly truncated, or deleted PaperCut server.log files. Specific log entries include "ERROR No suitable driver found for jdbc:no:x" and "ERROR DatabaseUtils - Database error looking up cardID: VALUES CAST".
In 2023, a similar critical flaw (CVE-2023-27350, CVSS score: 9.8) was exploited by Russian threat actors and the Lace Tempest group to deliver Cl0p and LockBit ransomware. Users with exposed PaperCut servers should immediately restrict internet access to trusted IP addresses using firewall rules and network access controls.
