Attackers Chain Two PaperCut Flaws to Execute Code Without Authentication

Security researchers have identified that attackers are chaining two vulnerabilities in PaperCut software to execute arbitrary code without authentication. The company has released emergency patches to address these flaws, which appear to be in the early stages of exploitation.
Why it matters
Software supply chain vulnerabilities pose significant risks to enterprise security, as unauthenticated remote code execution can lead to widespread data breaches and system compromises.
Malicious actors are exploiting a newly patched security flaw in PaperCut NG and MF to execute arbitrary code on susceptible instances, as the company released a fresh emergency fix with additional hardening.
"This vulnerability gives an unauthenticated attacker remote control over PaperCut's trusted configuration, which could be used to execute arbitrary Java code inside the application's process," Huntress researchers John Hammond and Andrew Brandt said .
Specifically, an attacker can leverage an unauthenticated request to make changes to the server configuration and ultimately achieve code execution. Huntress has explained the flaw as follows -
In unpatched versions of PaperCut NG and PaperCut MF, a specifically crafted request can refer to one page that is rendered for the response, and another page that owns the component or action being executed.
Get smarter about the news
Sign up free for a feed built around what you actually care about, Dive Deeper research on any story, and the full text of every article.
Create free accountAlready have an account? Sign in