Interestana
Home/News/Attackers Exploit PaperCut Flaws for Unauthenticated Code Execution
The Hacker News3 min read

By Interestana AI Editorial — AI-drafted, human-overseen. How we report

Attackers Exploit PaperCut Flaws for Unauthenticated Code Execution

Attackers Exploit PaperCut Flaws for Unauthenticated Code Execution

Malicious actors are actively exploiting a recently patched security vulnerability in PaperCut NG and PaperCut MF, enabling them to execute arbitrary code on vulnerable systems without requiring any authentication. PaperCut, a company specializing in print management software, released an emergency update to address this critical flaw, which allows unauthenticated attackers to gain remote control over the software's configuration. This control can then be leveraged to execute arbitrary Java code within the application's environment.

The vulnerability, identified as CVE-2023-27350, was initially patched by PaperCut on March 15, 2023. However, threat actors quickly discovered a way to chain this vulnerability with another, previously disclosed flaw, CVE-2023-27349, to bypass the initial patch and achieve code execution. This chaining technique means that even systems that had applied the first patch are still at risk if they are vulnerable to the second flaw. The exploitation of CVE-2023-27350 allows attackers to gain access to the PaperCut server's internal network, potentially leading to further compromise of sensitive data and systems.

PaperCut NG and PaperCut MF are widely used print management solutions designed to help organizations track, manage, and reduce printing costs. They offer features such as user authentication, print job accounting, and secure print release. The software's widespread deployment across various industries makes this vulnerability a significant concern for many organizations. The ability for an unauthenticated attacker to execute code remotely means that attackers can potentially install malware, steal credentials, or disrupt business operations without needing any prior access or credentials to the target network.

Security researchers have noted that the exploitation of these vulnerabilities is particularly concerning due to the ease with which they can be chained. The initial patch for CVE-2023-27350 was intended to mitigate the risk, but the subsequent discovery of the chaining attack highlights the persistent cat-and-mouse game between software vendors and malicious actors. Organizations using PaperCut NG or MF are strongly advised to ensure they have applied the latest security updates provided by PaperCut, which include patches for both CVE-2023-27350 and CVE-2023-27349, and to monitor their systems for any signs of suspicious activity. The company has also recommended additional hardening steps to further secure their environments against such attacks.

Original source — read the full reporting at the publisher:

Read on The Hacker News

Get the weekly AI digest

AI news + new model releases, weekly. Drafted by our agents, reviewed by humans.

Read next