Interestana
Home/News/PaperCut Issues Second Patch for Exploited Print Software Flaws
BleepingComputer3 min read

By Interestana AI Editorial — AI-drafted, human-overseen. How we report

PaperCut Issues Second Patch for Exploited Print Software Flaws

PaperCut has issued a second emergency security update for its PaperCut NG and MF print management software, addressing two vulnerabilities that have been actively exploited in the wild. This second patch comes after researchers identified multiple methods to bypass the initial fixes that PaperCut released on April 16, 2024. The vulnerabilities, identified as CVE-2023-27350 and CVE-2023-27351, allow for remote code execution and unauthorized access to sensitive information within the print management system. The initial patch, released on April 16, was intended to mitigate these risks, but subsequent analysis by security researchers revealed that the fixes were not comprehensive enough to prevent exploitation.

Security researchers from Rapid7, a cybersecurity firm, were among those who discovered the bypass methods. Their analysis indicated that the initial patches did not fully address the root causes of the vulnerabilities, leaving systems susceptible to attack. PaperCut acknowledged these findings and stated that the second patch provides more robust protection against the identified exploitation techniques. The company is urging all users of PaperCut NG and MF to apply the latest update as soon as possible to secure their environments. The vulnerabilities, if exploited, could lead to significant security breaches, including the potential for attackers to gain control of affected servers, access confidential documents, and disrupt print operations.

PaperCut NG and MF are widely used print management solutions designed to help organizations control and manage their printing infrastructure, track print usage, and reduce waste. The software is deployed in a variety of sectors, including education, healthcare, and finance, making the security of these systems critical. The active exploitation of these flaws highlights the ongoing threat landscape for enterprise software and the importance of timely and effective patching. Organizations that utilize PaperCut software are advised to review their security configurations and ensure that all systems are updated to the latest version to prevent potential compromise. The company has not disclosed specific details about the number of organizations affected or the extent of any potential breaches, but the release of a second emergency patch underscores the severity of the situation.

Original source — read the full reporting at the publisher:

Read on BleepingComputer

Get the weekly AI digest

AI news + new model releases, weekly. Drafted by our agents, reviewed by humans.

Read next