PaperCut, the company behind print management software used by schools, universities, businesses and government agencies around the world, has rushed out emergency patches after confirming that hackers are actively exploiting a previously unknown flaw in its NG and MF products.
The vulnerability affects all versions of PaperCut NG and PaperCut MF, the two flagship products the company sells to help organizations track and control printing across their networks. As of publication, no CVE identifier has been assigned to the flaw, and PaperCut has not published technical details about how the vulnerability works, a common practice when a fix is still being rolled out and the company wants to avoid handing attackers a roadmap.
In a security advisory published this week, PaperCut confirmed the issue is not theoretical. “We are aware of confirmed customer incidents and are treating this matter with the highest priority,” the company said. According to reporting from BleepingComputer and SecurityWeek, PaperCut’s security team was able to reproduce the vulnerability after receiving information from a university that had already been compromised, giving a concrete sense of who is being targeted.
PaperCut released emergency patches for internet-facing servers on Friday, August 28, and is urging customers to install them immediately. For organizations that cannot patch right away, the company recommends disconnecting the application server from the internet entirely or, at minimum, restricting access to the web interface to trusted IP addresses through firewall rules.
The company also published a list of indicators that may show whether a server has already been compromised. These include unusual activity from the legitimate pc-app.exe process, which attackers appear to be abusing as part of the intrusion, and server.log files that have been unexpectedly truncated or deleted, a sign that an attacker may be trying to erase evidence of their activity. Administrators are also being told to check their logs for two specific database errors: “No suitable driver found for jdbc:no:x” and a “DatabaseUtils” error referencing a “cardID” lookup, both of which have shown up in confirmed incidents.
Neither PaperCut nor the researchers who reported the issue have attributed the attacks to a specific hacking group, and the investigation is ongoing.
This isn’t the company’s first brush with serious security trouble either: back in August 2023, we reported on critical PaperCut vulnerabilities that let attackers read, upload, and delete files on the application server without needing to log in — a flaw in versions of NG and MF prior to 22.1.3.
The disclosure is likely to draw extra attention because of PaperCut’s history. A previous flaw in the same product line, tracked as CVE-2023-27350, was exploited in 2023 by several ransomware operations, including Clop and LockBit, as well as the Bl00dy Ransomware Gang and a group linked to Iranian state hacking activity. Three separate PaperCut NG and MF vulnerabilities currently appear in the US Cybersecurity and Infrastructure Security Agency’s Known Exploited Vulnerabilities catalog, and two of those were used in ransomware attacks. Organizations still running unpatched PaperCut servers are being urged not to wait for a CVE number before acting.
Source: BleepingComputer, additional reporting from SecurityWeek
