PaperCut Races to Patch Zero-Day Flaw in Print Management Software
PaperCut is warning that hackers are actively exploiting a vulnerability in all versions of its PaperCut NG and PaperCut MF print management software in zero-day attacks. The company confirms customer incidents and says it is treating the matter with the highest priority. PaperCut urges organizations with internet-exposed Application Servers to immediately restrict access to their web interfaces using firewall rules or network access controls limited to trusted IP addresses.
The company has released emergency patches for customers running public-facing PaperCut NG and MF servers who cannot take other mitigating action. PaperCut says its security team reproduced the vulnerability using information provided by a university customer, but it has not shared technical details about the flaw or how attackers are exploiting it. So far, the company has not disclosed who is behind the attacks, what attackers do after compromising servers, or whether any data is being stolen.
PaperCut has shared indicators of compromise to help administrators check their systems. These include suspicious activity from the legitimate PaperCut pc-app.exe process, as well as server.log files that have been modified, deleted, or are missing. Admins should also look for specific errors in server.log, including "No suitable driver found for jdbc:no:x" and "Database error looking up cardID: VALUES CAST." PaperCut cautions that a lack of indicators does not mean a server is clean, and it promises to update its advisory with more guidance as the investigation continues.