By Interestana AI Editorial — AI-drafted, human-overseen. How we report
PaperCut Zero-Days Exploited for Data Theft
Two critical zero-day vulnerabilities within PaperCut NG and PaperCut MF, widely used print management software, have been actively exploited for data theft attacks following their recent patching. The vulnerabilities, identified as CVE-2023-27193 and CVE-2023-27194, were disclosed and patched by PaperCut last week. However, threat actors have been observed leveraging these flaws in the wild before the patches were widely deployed. The exploitation of these zero-days allows attackers to bypass authentication and gain unauthorized access to sensitive information. Specifically, CVE-2023-27193 is described as a path traversal vulnerability that enables attackers to read arbitrary files on the server, potentially exposing credentials or other confidential data. CVE-2023-27194, on the other hand, is an SQL injection vulnerability that allows attackers to manipulate database queries, leading to data exfiltration or unauthorized modification. These vulnerabilities affect specific versions of PaperCut NG and PaperCut MF. PaperCut NG versions prior to 22.0.37 and PaperCut MF versions prior to 22.0.37 are vulnerable. The company has urged all users to update their installations to the patched versions immediately to mitigate the risk of compromise. The exploitation of these vulnerabilities highlights a common trend where zero-day flaws are weaponized by malicious actors as soon as they become known, often before organizations have had the opportunity to apply security updates. The data theft attacks observed indicate that attackers are targeting the information stored within the PaperCut system, which can include user credentials, print job data, and potentially other sensitive organizational information. The Print Management Software market is a significant sector, with solutions like PaperCut providing essential services for businesses to manage and control their printing infrastructure, track usage, and reduce costs. The compromise of such systems can have far-reaching consequences, including regulatory non-compliance, reputational damage, and significant financial losses due to data breaches. Security researchers have been actively monitoring these attacks and have provided indicators of compromise (IOCs) to help organizations detect and respond to potential intrusions. The rapid exploitation of these vulnerabilities underscores the importance of prompt patching and robust security monitoring for all software, especially those that handle critical business operations and sensitive data. Organizations using PaperCut software are advised to verify their current version and apply the necessary updates without delay. Further analysis of the attack vectors and the specific data being targeted is ongoing by cybersecurity firms.
Original source — read the full reporting at the publisher:
Read on BleepingComputerGet the weekly AI digest
AI news + new model releases, weekly. Drafted by our agents, reviewed by humans.