Attackers Chain Two PaperCut Flaws to Achieve Unauthenticated Remote Code Execution

Malicious actors are exploiting a newly patched vulnerability in PaperCut NG and PaperCut MF print management software to execute arbitrary code on affected servers, according to research from Huntress and reporting by The Hacker News. PaperCut released an emergency fix with additional hardening after the flaw, which does not yet have an assigned CVE identifier, was found being exploited in the wild.

Huntress researchers John Hammond and Andrew Brandt said the vulnerability gives an unauthenticated attacker remote control over PaperCut’s trusted configuration, which can be used to execute arbitrary Java code inside the application’s process. The flaw stems from how PaperCut’s authorization check handles a specifically crafted request: an attacker can reference one page that gets rendered in the response while a different page actually owns the component or action being executed, allowing the authorization check to trust the rendered page and miss the permission requirements tied to the executed action.

PaperCut print management software is widely deployed across schools, government agencies, healthcare systems and corporate print environments, making unauthenticated remote code execution a significant exposure wherever an instance is reachable from an untrusted network. Organizations running PaperCut NG or MF are advised to apply the emergency patch immediately and review Huntress’s indicators for signs of prior exploitation.

Comments

Leave a Reply

Your email address will not be published. Required fields are marked *