PaperCut: Hot topics

PaperCut Software security response team is investigating active exploitation of a vulnerability affecting PaperCut NG and PaperCut MF.

We are aware of confirmed customer incidents and are treating this matter with the highest priority. Our investigation is ongoing. We will update this security bulletin as verified information becomes available, including indicators of compromise and remediation guidance.

 

 

Security Bulletin (November 2023)

Security Bulletin (May 2024)

Some SVEs relating to older versions of PaperCut NG/MF have been rescored and/or split. These are NOT new CVEs and remain fixed. They were rescored after extensive discussions with the security researchers who reported them. These CVEs reflect the worst-case scenario where an Administrator has granted local login access to standard network users on a Windows PaperCut NG/MF server. Additionally, two CVEs have been split into separate CVEs to allow the security researchers who reported them to be separately attributed to CVEs referencing two instances of the same vulnerability type with different paths to different reporters.

Archiv

In unserem Hinweisarchiv finden Sie wertvollen Sicherheitshinweisen und Informationen aus vergangenen Jahren. Nutzen Sie unser Archiv jederzeit zum Nachlesen und Nachschlagen für Sie relevanter Informationen.

weiterlesen ...