PaperCut: la patch di emergenza 2 chiude la catena RCE sfruttata

PaperCut: emergency patch 2 closes the exploited RCE chain

PaperCut has released Emergency Patch Release 2 after researchers demonstrated that the first fix could be bypassed against a pre-authentication remote code execution chain that was already being actively exploited. The flaw affects PaperCut NG and MF, products used in schools, hospitals, and offices, so the potential target base is enormous. Huntress observed real-world activity and reconstructed the entire chain on a clean installation, confirming that the risk was not theoretical. The problem is compounded by the fact that many installations remain exposed and that attackers can use the print server as an initial entry point. For defenders, the priority is to apply the correct patch immediately, check for compromises, and look for signs of reconnaissance or abnormal access.

Source: Vulnerability – InfoTech News

Leave a Reply

Your email address will not be published. Required fields are marked *


Post Comment