PaperCut Releases Emergency Patch for Exploited Zero-Day
Vulnerabilities
A CVE identifier has not yet been assigned, but PaperCut is urging NG/MF users to install patches and implement mitigations.
PaperCut Software is warning users of its NG and MF print management solutions that a zero-day vulnerability is being exploited in the wild.
The flaw has yet to be assigned a CVE identifier and no technical details have been shared. The vendor released emergency patches on Friday and urged customers to install them.
PaperCut also recommends disconnecting the application server from the internet and restricting access to trusted IPs.
“We are aware of confirmed customer incidents and are treating this matter with the highest priority. Our investigation is ongoing,” the company said in its advisory.
It’s unclear who is behind the exploitation of the zero-day vulnerability.
PaperCut has shared some indicators of compromise (IoCs), including the name of a suspicious file, pc-app.exe, which indicates that the attackers...
Copyright of this story solely belongs to securityweek.com. To see the full text click HERE