AI Security AI安全 8h ago Updated 3h ago 更新于 3小时前 43

PaperCut Releases Emergency Patch for Exploited Zero-Day PaperCut 发布针对已利用零日漏洞的紧急补丁

PaperCut NG/MF print management solutions have a zero-day vulnerability being actively exploited in the wild The flaw allows unauthenticated remote code execution via Java code injection in the application process Emergency patches were released; approximately 1,000 instances are exposed, mostly in North America and Europe Attackers are delivering malware (pc-app.exe) and modifying/deleting server.log files to cover tracks CISA has not yet added this to its Known Exploited Vulnerabilities catalo PaperCut NG/MF打印管理解决方案发现零日漏洞正在被利用,尚未分配CVE编号 攻击者可通过漏洞获取未认证远程访问权限,在应用进程内执行任意Java代码 约1000个PaperCut实例暴露在互联网上,主要位于北美和欧洲 入侵指标包括可疑文件pc-app.exe和被截断/删除的server.log文件

68
Hot 热度
62
Quality 质量
55
Impact 影响力

Analysis 深度分析

TL;DR

  • PaperCut NG/MF print management solutions have a zero-day vulnerability being actively exploited in the wild
  • The flaw allows unauthenticated remote code execution via Java code injection in the application process
  • Emergency patches were released; approximately 1,000 instances are exposed, mostly in North America and Europe
  • Attackers are delivering malware (pc-app.exe) and modifying/deleting server.log files to cover tracks
  • CISA has not yet added this to its Known Exploited Vulnerabilities catalog

Why It Matters

This zero-day affects critical print infrastructure that many enterprises rely on, with unauthenticated attackers gaining remote control over trusted configuration. The active exploitation with malware delivery makes this an urgent security concern for IT administrators managing print management systems.

Technical Details

  • Vulnerability allows unauthenticated remote code execution by exploiting PaperCut's trusted configuration handling
  • Attackers can execute arbitrary Java code inside the application's process
  • Indicators of compromise include suspicious pc-app.exe file and truncated/deleted server.log files
  • PaperCut recommends disconnecting the application server from the internet and restricting access to trusted IPs
  • Emergency patches were released on Friday; no CVE identifier assigned yet

Industry Insight

  • Organizations using PaperCut NG/MF should immediately apply emergency patches and audit for signs of compromise
  • The vulnerability joins a pattern of print management and infrastructure software being targeted (related to Citrix NetScaler, Gitea exploits)
  • Consider network segmentation for print servers and monitoring for unusual Java process activity
  • CISA's KEV catalog typically adds active zero-days within days; expect this to be listed soon

TL;DR

  • PaperCut NG/MF打印管理解决方案发现零日漏洞正在被利用,尚未分配CVE编号
  • 攻击者可通过漏洞获取未认证远程访问权限,在应用进程内执行任意Java代码
  • 约1000个PaperCut实例暴露在互联网上,主要位于北美和欧洲
  • 入侵指标包括可疑文件pc-app.exe和被截断/删除的server.log文件

为什么值得看

对于使用PaperCut打印管理系统的企业IT安全团队至关重要,需立即评估系统暴露风险并采取缓解措施。该漏洞属于远程代码执行(RCE)类型,可直接导致系统被完全控制。

技术解析

  • 漏洞允许未认证攻击者远程控制PaperCut的受信任配置,在应用进程内执行任意Java代码,属于高危远程代码执行漏洞
  • 攻击者通过pc-app.exe等恶意文件投递后渗透工具,并删除或截断server.log文件以清除入侵痕迹
  • 约1000个PaperCut实例暴露在互联网上,主要集中在北美和欧洲地区
  • 这是PaperCut NG/MF系列中第三个被CISA已知利用漏洞目录收录的安全缺陷,前两个漏洞已被用于勒索软件攻击

行业启示

  • 打印管理服务器不应直接暴露在互联网上,应通过VPN或网络隔离进行访问控制
  • 零日漏洞应急响应需快速部署补丁,同时采取临时缓解措施如网络隔离和访问限制
  • 定期审查和监控日志文件完整性是检测入侵的重要指标,server.log被篡改往往是攻击者清除痕迹的信号

Disclaimer: The above content is generated by AI and is for reference only. 免责声明:以上内容由 AI 生成,仅供参考。

Security 安全 Research 科学研究