ZeroHour
Infosecurity Magazinepublished ()ingested Alessandro Mascellino1

PaperCut Software Flaw Sparks Ransomware Attacks, CISA Warns

criticalRansomwareimportance 60CVE-2023-27350

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2023-27350
Authentication Bypass Leading to SYSTEM RCE in PaperCut MF/NG

PaperCut MF and PaperCut NG print management software contain an improper access control flaw (CWE-284) in the SetupCompleted class that allows an unauthenticated attacker to bypass authentication and reach internal administrative functionality. The flaw is triggered by sending crafted, unauthenticated requests to the PaperCut application's web interface, without requiring valid user credentials. A successful attacker gains the ability to execute code in the context of the SYSTEM account on the PaperCut server, typically a Windows print server, giving full control of that host. Any organization running PaperCut MF or NG is potentially affected, and exposure is highest where the server's web interface is reachable from the internet or by untrusted networks. Exploitation is confirmed in the wild: CISA added the flaw to the KEV on 2023-04-21 with known ransomware use, and EPSS rates exploitation probability at 100% within 30 days.

Do: Apply the vendor's updates as instructed (this is the required action in CISA KEV) — upgrade PaperCut MF/NG to the patched releases listed in PaperCut's security advisory rather than relying on unpatched installs. Until patched, restrict network access to the PaperCut web/admin interface so it is reachable only from trusted hosts, and check the server for signs of compromise given known ransomware use. Prioritize internet-facing PaperCut servers, which public scans show are exposed in the thousands.

9.8100% KEV ransomware PoC ×3
  • PaperCut MF
  • PaperCut NG
masstens of thousands of organizations (~70k+) and millions of users; thousands of internet-exposed PaperCut servers
Full article308 words · extracted from infosecurity-magazine.com · click to collapse

The US Cybersecurity and Infrastructure Security Agency (CISA) has warned against a critical flaw discovered in PaperCut software, which has now been linked to a series of ransomware attacks.

The vulnerability (CVE-2023-27350) in PaperCut, a widely adopted print management solution, has allowed cyber-criminals to remotely execute malicious code without requiring any authentication credentials. 

Consequently, these attackers have successfully deployed ransomware and illegally accessed sensitive data.

Read more on this vulnerability here: Microsoft Blames Clop Affiliate for PaperCut Attacks

In response to the escalating threat, CISA and the Federal Bureau of Investigation (FBI) issued a cautionary advisory on Thursday urging users to take immediate action to mitigate the risk.

“According to FBI observed information, malicious actors exploited CVE-2023-27350 beginning in mid-April 2023 and continuing through the present,” reads the technical write-up.

In early May 2023, the Education Facilities Subsector became a prime target for the Bl00dy Ransomware Gang, as reported by the FBI. The group specifically aimed to exploit vulnerable PaperCut servers within the Subsector, resulting in data exfiltration, system encryption and the issuance of ransom demands.

“The Bl00dy Ransomware Gang left ransom notes on victim systems demanding payment in exchange for the decryption of encrypted files.”

The joint advisory provides detection methods for the exploitation of CVE-2023-27350 as well as indicators of compromise (IOCs) associated with Bl00dy Ransomware Gang activity. 

FBI and CISA strongly encouraged users and administrators to apply patches immediately or workarounds if unable to patch. The agencies especially encourage organizations that did not patch immediately to assume compromise and hunt for malicious activity using the detection signatures in the advisory. 

If potential compromise is detected, organizations should apply the incident response recommendations included in the document.

Its publication comes a couple of months after the FBI released a statement about a cyber-incident at one of its highest-profile field offices.

Text extracted automatically; images, tables and formatting may be missing. Original: https://www.infosecurity-magazine.com/news/papercut-software-flaw-sparks/