PaperCut Software has issued an urgent security update for its NG and MF print management systems due to a zero-day vulnerability actively being exploited. This security flaw, which is yet to receive a CVE identifier, has prompted PaperCut to release emergency patches, urging users to implement them without delay.
Immediate Security Measures
The company has advised users to disconnect the application server from the internet and restrict access to trusted IP addresses as an immediate precaution. In their security advisory, PaperCut emphasized the critical nature of the situation, confirming multiple incidents among its user base. They assured that the investigation into the vulnerability is ongoing.
Indicators of Compromise
While the identity of the attackers remains unknown, PaperCut has disclosed several indicators of compromise (IoCs). Among these is a suspicious file named pc-app.exe, suggesting the deployment of malware or other hostile tools. Furthermore, anomalies such as unexpectedly truncated or deleted server.log files could signal an attempted breach, with attackers potentially trying to erase their tracks.
Previous Vulnerabilities and Current Exposure
This incident is not unprecedented for PaperCut NG/MF, as previous vulnerabilities have been documented in CISA’s Known Exploited Vulnerabilities catalog. Additionally, two earlier vulnerabilities have been linked to ransomware attacks. As of now, approximately 1,000 PaperCut servers are exposed online, primarily located in North America and Europe, according to data from the ShadowServer Foundation.
In light of these developments, PaperCut is urging its customers to apply the patches promptly to safeguard their systems and prevent potential exploitation.
