PaperCut print management software vulnerabilities are actively exploited in zero-day attacks targeting enterprise networks worldwide, according to alerts issued by cybersecurity agencies and software developers in April 2023. Attackers are leveraging unauthenticated remote code execution flaws to deploy malicious payloads directly onto vulnerable servers.
PaperCut Zero-Day Flaws Under Active Attack
Print management outfit PaperCut confirmed that its Application Server software contains critical security vulnerabilities tracked as CVE-2023-27350 and CVE-2023-27351. According to an advisory published by BleepingComputer, the flaws affect PaperCut NG and PaperCut MF editions. Threat actors are chaining these vulnerabilities to bypass authentication and execute arbitrary code with SYSTEM privileges on Windows environments, extending similar risk to macOS and Linux servers.
The Cybersecurity and Infrastructure Security Agency (CISA) added the flaws to its Known Exploited Vulnerabilities catalog. CISA directed federal agencies to apply vendor-supplied patches immediately to mitigate ongoing network intrusion attempts.
Scope of Impact and Exploitation Vectors
According to findings from Huntress and other incident response firms, threat actors use the exploit to deploy remote access trojans and coin miners. Internet-exposed PaperCut servers lacking proper perimeter access controls face immediate compromise. Security researchers observed malicious scripts downloading secondary payloads directly from external command-and-control infrastructure.
Organizations running PaperCut MF or NG versions 8.0 up to 22.0.3 are urged to examine their application logs. Suspicious indicators include unexpected process creation originating from the PaperCut server application directory or unauthorized administrative account creation.
Mitigation and Patch Availability
PaperCut released patched versions—specifically version 22.0.4 and corresponding hotfixes for earlier supported builds—to remediate the vulnerabilities. System administrators unable to apply patches immediately must implement network-level mitigations. According to security advisories, restricting external access to PaperCut administration ports (typically TCP ports 9191 and 9192) via firewall rules prevents external exploitation attempts.
Related reading