Horizon Alert
Summary of the vulnerability and why it matters
The vulnerability impacts PaperCut NG and MF software. A flaw in the setup process allows attackers to bypass authentication. This could enable unauthorized access and the execution of malicious code on affected systems.
- Vulnerable PaperCut software
- Flaw allows authentication bypass
- Potential for code execution
Attack Path
How an attacker could exploit the issue
An attacker can exploit a vulnerability to bypass authentication and execute arbitrary code on affected systems. This bypass is possible due to an improper access control flaw within the SetupCompleted class. Authentication is not a prerequisite for an attacker to leverage this vulnerability. The attacker can gain system-level privileges, enabling them to execute commands without authorization.
- External network exposure required.
- Unauthenticated attacker gains access.
- Trigger bypass and execute code.
Live Threat
Current exploitation, exposure, and threat context
The PaperCut MF and NG software, used for print management, has a critical vulnerability that allows unauthenticated remote attackers to bypass security controls and execute arbitrary code on affected systems. This means attackers do not need any credentials or special access to exploit this flaw. The vulnerability has been actively exploited in the wild, with evidence of its use dating back to April 2023. Threat actors have used this vulnerability to deploy ransomware, conduct data theft, and gain further access to victim networks. Given the ease of exploitation, the critical severity, and confirmed real-world attacks, this vulnerability presents a significant and urgent risk to organizations running affected versions of PaperCut.
- Likely attacker skill level: Low
- Required access or conditions: None, remote access
- Business risk or urgency: Critical, urgent patching required
Priority actions
Operational Fix
Recommended remediation, mitigation, and detection steps
The identified vulnerability allows for authentication bypass and arbitrary code execution on affected PaperCut NG and MF installations. This presents a significant risk to organizations, potentially leading to unauthorized system access and control. Addressing this vulnerability is critical to maintaining the security and integrity of systems managing print operations.
- Find PaperCut installations.
- Isolate exposed systems.
- Update software and verify.
- Monitor for related activity.