ZeroHour
The Hacker Newspublished ()ingested @TheHackersNews

CISA Adds PaperCut NG/MF CSRF Vulnerability to KEV Catalog Amid Active Exploitation

highExploit / PoC exploited in the wildimportance 60CVE-2023-2533

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2023-2533
CSRF Flaw in PaperCut NG/MF Enables Security Changes and Arbitrary Code Execution

CVE-2023-2533 is a cross-site request forgery (CSRF, CWE-352) flaw in PaperCut's NG and MF print-management software, where state-changing requests submitted through the product's web console are not adequately verified as originating from a trusted source. An attacker triggers it by persuading an authenticated PaperCut administrator or user to follow attacker-controlled content, such as a crafted link, while their web session is active. Under specific conditions, the attacker can then alter security settings or execute arbitrary code in the context of the victim's session. Any organization running PaperCut NG or MF is potentially affected, though the available data does not specify exact affected or fixed version ranges. The flaw was added to CISA's Known Exploited Vulnerabilities catalog on 2025-07-28, confirming active exploitation; no public proof-of-concept is known and CVSS is not yet scored, but EPSS puts the probability of exploitation within 30 days at 29.2% (98th percentile).

Do: Apply PaperCut's mitigations per the vendor's security advisory, including upgrading NG and MF to the fixed release specified there, and audit recent security-setting changes for signs of tampering; federal users must follow applicable BOD 22-01 guidance (including for cloud services) or discontinue use if mitigations are unavailable. Since CSRF requires an active authenticated session, restrict admin-console access and treat phishing links aimed at PaperCut administrators as a live vector.

8.829% KEV PoC
  • PaperCut NG/MF
largetens of thousands to ~100,000 organizations running PaperCut NG/MF (vendor cites 100k+ deployments), with only a subset of instances internet-exposed
Full article380 words · extracted from thehackernews.com · click to collapse

Ravie LakshmananJul 29, 2025Vulnerability / Software Security

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Monday added a high-severity security vulnerability impacting PaperCutNG/MF print management software to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence of active exploitation in the wild.

The vulnerability, tracked as CVE-2023-2533 (CVSS score: 8.4), is a cross-site request forgery (CSRF) bug that could result in remote code execution.

"PaperCut NG/MF contains a cross-site request forgery (CSRF) vulnerability, which, under specific conditions, could potentially enable an attacker to alter security settings or execute arbitrary code," CISA said in an alert.

PaperCut NG/MF is commonly used by schools, businesses, and government offices to manage print jobs and control network printers. Because the admin console typically runs on internal web servers, an exploited vulnerability here could give attackers an easy foothold into broader systems if overlooked.

In a potential attack scenario, a threat actor could leverage the flaw to target an admin user with a current login session, and deceive them into clicking on a specially crafted link that leads to unauthorized changes.

It's currently not known how the vulnerability is being exploited in real-world attacks. But given that shortcomings in the software solution have been abused by Iranian nation-state actors as well as e-crime groups like Bl00dy, Cl0p, and LockBit ransomware for initial access, it's essential that users apply necessary updates, if not already.

At the time of writing, no public proof-of-concept is available, but attackers could exploit the bug through a phishing email or a malicious site that tricks a logged-in admin into triggering the request. Mitigation requires more than patching—organizations should also review session timeouts, restrict admin access to known IPs, and enforce strong CSRF token validation.

Pursuant to Binding Operational Directive (BOD) 22-01, Federal Civilian Executive Branch (FCEB) agencies are required to update their instances to a patched version by August 18, 2025.

Admins should cross-check with MITRE ATT&CK techniques like T1190 (Exploit Public-Facing Application) and T1071 (Application Layer Protocol) to align detection rules. For broader context, tracking PaperCut incidents in relation to ransomware entry points or initial access vectors can help shape long-term hardening strategies.

Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post.

Text extracted automatically; images, tables and formatting may be missing. Original: https://thehackernews.com/2025/07/cisa-adds-papercut-ngmf-csrf.html