New PaperCut critical bug exposes unpatched servers to RCE attacks

Teilen:

PaperCut recently fixed a critical security vulnerability in its NG/MF print management software that allows unauthenticated attackers to gain remote code execution on unpatched Windows servers.

Tracked as CVE-2023-39143, the flaw results from a chain of two path traversal weaknesses discovered by Horizon3 security researchers that enable threat actors to read, delete, and upload arbitrary files on compromised systems following low-complexity attacks that don’t require user interaction.

While it only impacts servers in non-default configurations where the external device integration setting is toggled, Horizon3 said in a report published on Friday that most Windows PaperCut servers have it enabled.

“This setting is on by default with certain installations of PaperCut, such as the PaperCut NG Commercial version or PaperCut MF,” Horizon3 said.

“Based on sample data we have collected at Horizon3 from real-world environments, we estimate that the vast majority of PaperCut installations are running on Windows with the external device integration setting turned on.”

You can use the following command to check if a server is vulnerable to CVE-2023-39143 attacks and is running on Windows (a 200 response indicates the server needs patching):

curl -w "%{http_code}" -k --path-as-is "https://<IP>:<port>/custom-report-example/......deploymentsharpiconshome-app.png"

Admins who cannot immediately install security updates (as Horizon3 advises) can add only the IP addresses that need access to an allowlist using these instructions.

Shodan search shows that roughly 1,800 PaperCut servers are currently exposed online, although not all are vulnerable to CVE-2023-39143 attacks.

PaperCut print servers exposed online
PaperCut print servers exposed online (Shodan)

Targeted by ransomware gangs, state hackers

PaperCut servers were targeted by several ransomware gangs earlier this year by exploiting another critical unauthenticated RCE vulnerability (CVE-2023–27350) and a high-severity information disclosure flaw (CVE-2023–27351).

The company disclosed on April 19th that these vulnerabilities were being actively exploited in attacks, urging admins and security teams to upgrade their servers urgently.

A few days after the initial disclosure, Horizon3 security researchers released an RCE Proof-of-Concept (PoC) exploit, opening the door for additional threat actors to target vulnerable servers.

Microsoft linked the attacks targeting PaperCut servers to the Clop and LockBit ransomware gangs, who used the access to steal corporate data from compromised systems.

In these data theft attacks, the ransomware operation took advantage of the ‘Print Archiving‘ feature that saves all documents sent through the PaperCut printing servers.

Almost two weeks after, Microsoft revealed that Iranian state-backed hacking groups tracked as Muddywater und APT35 also joined the ongoing assault.

CISA added the CVE-2023–27350 RCE bug to its list of actively exploited vulnerabilities on April 21st, ordering all U.S. federal agencies to secure their servers by May 12th, 2023.

 

(c) Lawrence Abrams

Kommentar verfassen

Deine E-Mail-Adresse wird nicht veröffentlicht. Erforderliche Felder sind mit * markiert

lade-bild
London, GB
8:41 am, Mai 19, 2025
Wetter-Symbol 12°C
L: 11° | H: 13°
overcast clouds
Luftfeuchtigkeit: 78 %
Druck: 1021 mb
Wind: 7 mph NNE
Windböe: 0 mph
UV-Index: 0
Niederschlag: 0 mm
Wolken: 100%
Regen Chance: 0%
Sichtbarkeit: 10 km
Sonnenaufgang: 5:02 am
Sonnenuntergang: 8:51 pm
TäglichStündlich
Tägliche VorhersageStündliche Vorhersage
Today 10:00 pm
Wetter-Symbol
11° | 13°°C 0 mm 0% 11 mph 78 % 1021 mb 0 mm/h
Tomorrow 10:00 pm
Wetter-Symbol
10° | 21°°C 0 mm 0% 9 mph 69 % 1022 mb 0 mm/h
Mi. Mai 21 10:00 pm
Wetter-Symbol
14° | 22°°C 0 mm 0% 12 mph 63 % 1020 mb 0 mm/h
Do. Mai 22 10:00 pm
Wetter-Symbol
11° | 18°°C 0 mm 0% 12 mph 64 % 1023 mb 0 mm/h
Fr. Mai 23 10:00 pm
Wetter-Symbol
7° | 19°°C 0 mm 0% 9 mph 69 % 1024 mb 0 mm/h
Today 10:00 am
Wetter-Symbol
12° | 14°°C 0 mm 0% 7 mph 78 % 1021 mb 0 mm/h
Today 1:00 pm
Wetter-Symbol
14° | 18°°C 0 mm 0% 9 mph 67 % 1021 mb 0 mm/h
Today 4:00 pm
Wetter-Symbol
16° | 19°°C 0 mm 0% 11 mph 52 % 1020 mb 0 mm/h
Today 7:00 pm
Wetter-Symbol
17° | 17°°C 0 mm 0% 9 mph 46 % 1020 mb 0 mm/h
Today 10:00 pm
Wetter-Symbol
13° | 13°°C 0 mm 0% 6 mph 63 % 1021 mb 0 mm/h
Tomorrow 1:00 am
Wetter-Symbol
11° | 11°°C 0 mm 0% 5 mph 66 % 1022 mb 0 mm/h
Tomorrow 4:00 am
Wetter-Symbol
10° | 10°°C 0 mm 0% 5 mph 69 % 1021 mb 0 mm/h
Tomorrow 7:00 am
Wetter-Symbol
11° | 11°°C 0 mm 0% 6 mph 63 % 1022 mb 0 mm/h
Name Preis24H (%)
Bitcoin(BTC)
€91,831.07
-0.79%
Ethereum(ETH)
€2,142.07
-4.25%
Fesseln(USDT)
€0.89
0.00%
XRP(XRP)
€2.07
-2.99%
Solana(SOL)
€144.24
-4.92%
USDC(USDC)
€0.89
0.00%
Dogecoin(DOGE)
€0.194922
-0.98%
Shiba Inu(SHIB)
€0.000013
-2.92%
Pepe(PEPE)
€0.000012
0.43%
Peanut das Eichhörnchen(PNUT)
€0.285736
-7.51%
Nach oben scrollen