PaperCut Releases Emergency Patch for Exploited Zero-Day
PaperCut NG/MF print management solutions have a zero-day vulnerability being actively exploited in the wild The flaw allows unauthenticated remote code execution via Java code injection in the application process Emergency patches were released; approximately 1,000 instances are exposed, mostly in North America and Europe Attackers are delivering malware (pc-app.exe) and modifying/deleting server.log files to cover tracks CISA has not yet added this to its Known Exploited Vulnerabilities catalo
Analysis
TL;DR
- PaperCut NG/MF print management solutions have a zero-day vulnerability being actively exploited in the wild
- The flaw allows unauthenticated remote code execution via Java code injection in the application process
- Emergency patches were released; approximately 1,000 instances are exposed, mostly in North America and Europe
- Attackers are delivering malware (pc-app.exe) and modifying/deleting server.log files to cover tracks
- CISA has not yet added this to its Known Exploited Vulnerabilities catalog
Why It Matters
This zero-day affects critical print infrastructure that many enterprises rely on, with unauthenticated attackers gaining remote control over trusted configuration. The active exploitation with malware delivery makes this an urgent security concern for IT administrators managing print management systems.
Technical Details
- Vulnerability allows unauthenticated remote code execution by exploiting PaperCut's trusted configuration handling
- Attackers can execute arbitrary Java code inside the application's process
- Indicators of compromise include suspicious pc-app.exe file and truncated/deleted server.log files
- PaperCut recommends disconnecting the application server from the internet and restricting access to trusted IPs
- Emergency patches were released on Friday; no CVE identifier assigned yet
Industry Insight
- Organizations using PaperCut NG/MF should immediately apply emergency patches and audit for signs of compromise
- The vulnerability joins a pattern of print management and infrastructure software being targeted (related to Citrix NetScaler, Gitea exploits)
- Consider network segmentation for print servers and monitoring for unusual Java process activity
- CISA's KEV catalog typically adds active zero-days within days; expect this to be listed soon
Disclaimer: The above content is generated by AI and is for reference only.