PaperCut flaw in print management sw exposes servers to RCE
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2023-27350 | Authentication Bypass Leading to SYSTEM RCE in PaperCut MF/NG PaperCut MF and PaperCut NG print management software contain an improper access control flaw (CWE-284) in the SetupCompleted class that allows an unauthenticated attacker to bypass authentication and reach internal administrative functionality. The flaw is triggered by sending crafted, unauthenticated requests to the PaperCut application's web interface, without requiring valid user credentials. A successful attacker gains the ability to execute code in the context of the SYSTEM account on the PaperCut server, typically a Windows print server, giving full control of that host. Any organization running PaperCut MF or NG is potentially affected, and exposure is highest where the server's web interface is reachable from the internet or by untrusted networks. Exploitation is confirmed in the wild: CISA added the flaw to the KEV on 2023-04-21 with known ransomware use, and EPSS rates exploitation probability at 100% within 30 days. Do: Apply the vendor's updates as instructed (this is the required action in CISA KEV) — upgrade PaperCut MF/NG to the patched releases listed in PaperCut's security advisory rather than relying on unpatched installs. Until patched, restrict network access to the PaperCut web/admin interface so it is reachable only from trusted hosts, and check the server for signs of compromise given known ransomware use. Prioritize internet-facing PaperCut servers, which public scans show are exposed in the thousands. | 9.8 | 100% | KEV ransomware PoC ×3 |
| masstens of thousands of organizations (~70k+) and millions of users; thousands of internet-exposed PaperCut servers | |
| CVE-2023-39143 | PaperCut NG and PaperCut MF before 22.1.3 on Windows allow path traversal, enabling attackers to upload, read, or delete arbitrary files. PaperCut NG and PaperCut MF before 22.1.3 on Windows allow path traversal, enabling attackers to upload, read, or delete arbitrary files. This leads to remote code execution when external device integration is enabled (a very common configuration). NVD description · AI analysis pending | 9.8 | 81% | PoC |
| — |
Full article366 words · extracted from securityaffairs.com · click to collapse

Researchers discovered a vulnerability in PaperCut NG/MF print management software that can lead to remote code execution.
Cybersecurity researchers at Horizon3 discovered a high-severity vulnerability, tracked as CVE-2023-39143 (CVSS score: 8.4), in PaperCut print management software for Windows.
An attacker can exploit the vulnerability to gain remote code execution under specific conditions.
The vulnerability CVE-2023-39143 is a path traversal that can allow attackers to read, delete, and upload arbitrary files. The vulnerability affects PaperCut NG/MF prior to version 22.1.3.
“CVE-2023-39143 enables unauthenticated attackers to potentially read, delete, and upload arbitrary files to the PaperCut MF/NG application server, resulting in remote code execution in certain configurations.” reads the advisory published by Horizon3. “In particular, the vulnerability affects PaperCut servers running on Windows. File upload leading to remote code execution is possible when the external device integration setting is enabled. This setting is on by default with certain installations of PaperCut, such as the PaperCut NG Commercial version or PaperCut MF.”
Horizon3 researchers estimate that most of the PaperCut installations are running on Windows with the external device integration setting turned on.
The issue was addressed with the release of PaperCut NG/MF patch version 22.1.3.
Below is the timeline for this issue:
- May 30, 2023: Horizon3 sends initial disclosure to the PaperCut team
- May 31, 2023: PaperCut acknowledges receipt of disclosure
- June 5, 2023: Horizon3 updates disclosure to include impact of remote code execution
- June 8, 2023: PaperCut confirms it is able to validate findings in disclosure
- June/July 2023: Horizon3/PaperCut work together to test interim builds and coordinate disclosure
- July 24, 2023: Horizon3 reserves CVE-2023-39143 with MITRE
- July 25, 2023: PaperCut releases patch version 22.1.3
- Aug. 4, 2023: This advisory
In April another actively exploited issue affecting PaperCut servers, tracked as CVE-2023-27350 (CVSS score: 9.8), made the headlines.
“Compared to CVE-2023-27350, CVE-2023-39143 also does not require attackers to have any prior privileges to exploit, and no user interaction is required.” continues Horizon3. “In contrast to CVE-2023-27350, CVE-2023-39143 is more complex to exploit, involving multiple issues that must be chained together to compromise a server. It is not a “one-shot” RCE vulnerability.”
Follow me on Twitter: @securityaffairs and Facebook and Mastodon
(SecurityAffairs – hacking, CVE-2023-39143)
Text extracted automatically; images, tables and formatting may be missing. Original: https://securityaffairs.com/149191/security/papercut-rce-cve-2023-39143.html