Threat Intelligence Brief
Curated summary with source attribution
Source: huntress.com
Threat Risk: High
Victim: Organizations using PaperCut NG or MF print management software
Incident: Active exploitation of a pre-authentication RCE vulnerability chain in PaperCut software.
Impact: Complete remote takeover of the PaperCut Application Server, allowing arbitrary code execution.
Attacker: Unidentified threat actors
Analysis: Attackers are chaining an improper access control flaw with an unsafe dynamic class-loading vulnerability to achieve pre-authentication remote code execution. Huntress has observed active exploitation involving base64-encoded reconnaissance commands executed on targeted servers. This chain allows an attacker to completely compromise the Application Server process without any prior credentials.
Recommendations: Immediately apply emergency patches for PaperCut NG/MF versions 25 and 26.; Remove all public-facing exposure of the PaperCut web management interface.; Monitor for suspicious Java processes spawning command shells or unexpected .class files in server directories.
Source: Huntress
Editorial note: this post summarizes third-party reporting and links to the original source.
View Original Source