PaperCut under attack with an already exploited zero-day
PaperCut has confirmed that a vulnerability in the NG and MF products is being actively exploited in zero-day attacks. The company has released emergency patches for v25 and v26 and has warned of incidents already confirmed at some customers. Attackers could gain code execution by exploiting the trusted configuration of the print system, a particularly sensitive point because the software is often exposed internally to many users. PaperCut also recommended immediately restricting web access to trusted IPs only and isolating servers accessible from the Internet. The news is critical because print management systems often have elevated privileges and can become a springboard into the entire corporate network.
Source: The Hacker News


Leave a Reply