PaperCut has warned that attackers are actively exploiting an undisclosed vulnerability in all versions of its PaperCut NG and PaperCut MF print management software.

PaperCut zero-day attacks target exposed servers

PaperCut said it has confirmed attacks affecting customers. The company urged organisations with Internet-exposed PaperCut Application Servers to act immediately.

Administrators should restrict access to PaperCut web interfaces to trusted IP addresses. They can use firewall rules or network access controls to limit exposure.

The vulnerability affects every version of PaperCut NG and PaperCut MF. However, PaperCut has not yet disclosed technical details about the flaw or the attack method.

Company releases emergency patch

PaperCut said its security team reproduced the vulnerability after receiving information from a university customer.

It has released an emergency patch for customers with public-facing PaperCut servers who cannot apply other mitigations.

Organisations should first remove unnecessary Internet access where possible. They should then install the emergency patch and monitor their servers for signs of compromise.

PaperCut said it will update its advisory as the investigation develops.

Administrators should check for compromise

PaperCut shared several indicators that may suggest a server was compromised during the PaperCut zero-day attacks.

Administrators should investigate suspicious activity involving the legitimate pc-app.exe process. They should also check whether server.log files were altered, deleted or unexpectedly missing.

The company identified two suspicious errors that may appear in server logs:

ERROR No suitable driver found for jdbc:no:x

ERROR DatabaseUtils - Database error looking up cardID: VALUES CAST

However, PaperCut warned that the absence of these indicators does not prove that a server is safe.

Previous flaws attracted ransomware groups

PaperCut servers have faced active exploitation before. In April 2023, attackers exploited CVE-2023-27350, a critical flaw that allowed unauthenticated remote code execution.

Microsoft later linked some attacks to the Clop ransomware operation and reported intrusions associated with LockBit ransomware. Iranian state-backed groups and the Bl00dy Ransomware Gang also exploited vulnerable PaperCut servers.

PaperCut has not said who is behind the current attacks. It has also not confirmed what attackers do after compromising servers or whether they steal data.


0 responses to “PaperCut Warns of Active Zero-Day Attacks on Print Servers”