← Back to blog

PaperCut Vulnerabilities Chained for Unauthenticated Remote Code Execution

Attackers are chaining two flaws in PaperCut print management software to gain remote control without authentication. Organizations should patch immediately.

TL;DR

  • Two critical PaperCut flaws allow unauthenticated remote code execution
  • Attackers can gain full control of affected print servers
  • Vendor released emergency patches with additional hardening measures
  • Organizations using PaperCut NG/MF should update immediately
  • Exploitation does not require user credentials or interaction

Security researchers have discovered that attackers are actively exploiting a chain of two vulnerabilities in PaperCut print management software. These flaws allow malicious actors to execute arbitrary code on vulnerable systems without requiring any authentication.

The vulnerabilities affect both PaperCut NG and MF editions, giving attackers remote control over the application's trusted configuration. This access can be leveraged to run arbitrary Java code within the application environment, potentially leading to complete system compromise.

PaperCut has responded by releasing emergency security updates that include additional hardening measures. Organizations running these print management solutions should prioritize applying these patches immediately.

Vulnerability Details

  • The attack chain combines two separate security flaws in PaperCut NG and MF
  • No authentication is required for exploitation, making it highly dangerous
  • Attackers gain control over trusted configuration settings
  • Arbitrary Java code execution is possible within the application context
  • The vulnerabilities affect widely deployed print management infrastructure

Impact and Recommendations

  • Successful exploitation grants attackers remote control capabilities
  • Organizations may face unauthorized access to print services and connected systems
  • Emergency patches have been released by PaperCut with additional hardening
  • Immediate patching is critical for all PaperCut NG and MF installations
  • Network segmentation and monitoring can help limit potential damage

Sources

Sources

Security email updates

One digest email when we publish new security articles (TL;DR plus links to read more). Unsubscribe anytime from the message footer. See our Privacy Policy.

PaperCut Vulnerabilities Chained for Unauthenticated Remote Code Execution — Agent Breach Blog | Agent Breach