ZeroHour
Security Affairspublished ()ingested @securityaffairs

Iran-linked APT groups started exploiting Papercut flaw

criticalThreat actor exploited in the wildimportance 60CVE-2023-27350

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2023-27350
Authentication Bypass Leading to SYSTEM RCE in PaperCut MF/NG

PaperCut MF and PaperCut NG print management software contain an improper access control flaw (CWE-284) in the SetupCompleted class that allows an unauthenticated attacker to bypass authentication and reach internal administrative functionality. The flaw is triggered by sending crafted, unauthenticated requests to the PaperCut application's web interface, without requiring valid user credentials. A successful attacker gains the ability to execute code in the context of the SYSTEM account on the PaperCut server, typically a Windows print server, giving full control of that host. Any organization running PaperCut MF or NG is potentially affected, and exposure is highest where the server's web interface is reachable from the internet or by untrusted networks. Exploitation is confirmed in the wild: CISA added the flaw to the KEV on 2023-04-21 with known ransomware use, and EPSS rates exploitation probability at 100% within 30 days.

Do: Apply the vendor's updates as instructed (this is the required action in CISA KEV) — upgrade PaperCut MF/NG to the patched releases listed in PaperCut's security advisory rather than relying on unpatched installs. Until patched, restrict network access to the PaperCut web/admin interface so it is reachable only from trusted hosts, and check the server for signs of compromise given known ransomware use. Prioritize internet-facing PaperCut servers, which public scans show are exposed in the thousands.

9.8100% KEV ransomware PoC ×3
  • PaperCut MF
  • PaperCut NG
masstens of thousands of organizations (~70k+) and millions of users; thousands of internet-exposed PaperCut servers
Full article460 words · extracted from securityaffairs.com · click to collapse

Microsoft warns of Iran-linked APT groups that are targeting vulnerable PaperCut MF/NG print management servers.

Microsoft warns that Iran-linked APT groups have been observed exploiting the CVE-2023-27350 flaw in attacks against PaperCut MF/NG print management servers.

The CVE-2023-27350 flaw is a PaperCut MF/NG Improper Access Control Vulnerability. PaperCut MF/NG contains an improper access control vulnerability within the SetupCompleted class that allows authentication bypass and code execution in the context of SYSTEM.

On April 19th, Print management software provider PaperCut confirmed that it is aware of the active exploitation of the CVE-2023-27350 vulnerability.

The company received two vulnerability reports from the cybersecurity firm Trend Micro for high/critical severity security issues in PaperCut MF/NG. 

Now Microsoft observed Iran-linked groups Mango Sandstorm (aka Mercury or Muddywater) and Mint Sandstorm (aka Phosphorus or APT35) exploiting the above flaw.

“More actors are exploiting unpatched CVE-2023-27350 in print management software Papercut since we last reported on Lace Tempest. Microsoft has now observed Iranian state-sponsored threat actors Mint Sandstorm (PHOSPHORUS) & Mango Sandstorm (MERCURY) exploiting CVE-2023-27350.” reads a tweet published by the Microsoft Threat Intelligence team.

Microsoft experts highlighted that both APT groups started exploiting the flaw shortly after public POCs were published for CVE-2023-27350. The attacks show the ability of both groups to rapidly adapt their operations by adding new POC exploits to their arsenal.

The researchers believe the PaperCut exploitation activity by the Mint Sandstorm group is opportunistic, they observed the Iranian group targeing organizations across sectors and geographies.

The PaperCut exploitation activity by Mint Sandstorm appears opportunistic, affecting organizations across sectors and geographies. We previously reported on other Mint Sandstorm TTPs: https://t.co/uNHftjIYVv

— Microsoft Threat Intelligence (@MsftSecIntel) May 5, 2023

Microsoft reported that CVE-2023-27350 exploitation activity by the second Iranian APT, Mango Sandstorm, remains low. The state-sponsored hackers were observed using tools from prior intrusions to connect to their C2 infrastructure.

As more threat actors begin to use this vulnerability in their attacks, organizations are strongly urged to prioritize applying the updates provided by PaperCut to reduce their attack surface: https://t.co/CPnwNDkm36

— Microsoft Threat Intelligence (@MsftSecIntel) May 5, 2023
The IT giant urges organizations to address the CVE-2023-27350 vulnerability to prevent its exploitation by threat actors, including Iran-linked APT groups.

PaperCut MF and NG software should be immediately upgraded to versions 20.1.7, 21.2.11, and 22.0.9 and later.

We are in the final!

Please vote for Security Affairs (https://securityaffairs.com/) as the best European Cybersecurity Blogger Awards 2022 – VOTE FOR YOUR WINNERS
Vote for me in the sections where is reported Securityaffairs or my name Pierluigi Paganini

Please nominate Security Affairs as your favorite blog.

Nominate Pierluigi Paganini and Security Affairs here here: https://docs.google.com/forms/d/e/1FAIpQLSepvnj8b7QzMdLh7vWEDQDqohjBUsHyn3x3xRdYGCetwVy2DA/viewform

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, Iran)



Text extracted automatically; images, tables and formatting may be missing. Original: https://securityaffairs.com/145952/apt/iranian-apt-papercut-exploitation.html