PaperCut warns of NG, MF flaw used in zero-day attacks

PaperCut

PaperCut warns that hackers are actively exploiting a vulnerability in all versions of its PaperCut NG and PaperCut MF print management software in zero-day attacks.

The company says it is aware of confirmed attacks against customers and urges organizations with Internet-exposed PaperCut application servers to immediately restrict access to web interfaces to trusted IP addresses.

“PaperCut Software’s security response team is actively investigating exploitation of a vulnerability affecting PaperCut NG and PaperCut MF,” it reads urgent security advice published on Thursday.

image

“We are aware of confirmed customer incidents and are treating this matter with the highest priority.”

PaperCut says the vulnerability affects all versions of PaperCut NG and MF, but did not share details about the flaw or how it is being exploited.

The company says its security team reproduced the vulnerability using information provided by a customer to the university.

PaperCut has now released hotfixes for customers with public PaperCut NG/MF servers.

“This is an emergency fix for customers with public PaperCut NG/MF servers who cannot take other mitigations,” the announcement reads.

The company continues to warn customers whose application servers are exposed to the Internet to use firewall rules or network access controls to restrict their web interfaces to trusted IP addresses.

PaperCut also shared indicators of compromise that could indicate if a server has been compromised.

These include suspicious activity from the legitimate PaperCut pc-app.exe processes and server.log files that have been changed, deleted or missing.

Administrators should also look for the following errors in the server.log:


ERROR No suitable driver found for jdbc:no:x

ERROR DatabaseUtils - Database error looking up cardID: VALUES CAST

However, PaperCut cautions that the absence of indicators does not mean that the server has not been compromised.

At this time, PaperCut is not disclosing who is behind the attacks, what the attackers are doing after compromising the servers, or whether data has been stolen.

PaperCut says it will continue to update its advisory with additional indicators of compromise and remediation guidance as the investigation continues.

BleepingComputer has contacted PaperCut with questions about this exploit and will update the story when we hear back.

Previous PaperCut flaws used in attacks

PaperCut has a history of being a threat object following the disclosure of security vulnerabilities.

In April 2023, attackers began exploiting the CVE-2023-27350 PaperCut critical vulnerability, which allowed unauthenticated attackers to bypass authentication and remotely execute code on vulnerable servers.

Microsoft later linked some of these attacks to Operation Clop ransomware, which used vulnerable PaperCut servers to initially gain access to company networks. Microsoft also noticed intrusions that led to LockBit ransomware attacks.

Although PaperCut has a print backup feature that can store documents sent over a server, Klopp later told BleepingComputer that he used the vulnerabilities to initially access victims’ networks, rather than steal archived documents directly from PaperCut’s servers.

The exploit has spread to other threats, with Microsoft reporting that Iranian state hacking groups are also exploiting CVE-2023-27350.

CISA and the FBI issued a joint alert in May 2023 warning that the Bl00dy Ransomware Gang was also using vulnerable PaperCut servers in attacks against the education sector.


article image

Generic prevention scores can hide what happens after initial access. Once attackers use valid credentials, prevention plummets.

The 2026 Blue Report measures security techniques by techniques in 338 million simulations run in customer production environments.

Get the report

Leave a Reply

Your email address will not be published. Required fields are marked *