PaperCut zero-day: “Boring” print servers become domain-wide threats

PaperCut’s urgent zero-day advisory is raising concerns well beyond the vulnerability itself, particularly given how many PaperCut servers are exposed to the internet and the potential for unauthenticated SYSTEM-level access. I have SMEs who are weighing in on the real-world exposure, why traditional vulnerability scanning can miss an actively exploited zero-day, and why defenders need to focus on containment, outbound controls and hunting for compromise – not just patching.

John Strand, Owner, Black Hills Information Security https://www.linkedin.com/in/john-strand-a1b4b62

“This is yet another example where the people who most need to see this vulnerability disclosure probably aren’t going to be the people who actually see it. Any sane computer security or IT professional would not have a PaperCut server directly exposed to the internet for anyone to access. But I just ran a quick check, and there are more than 100,000 PaperCut servers exposed directly to the internet right now. That’s the problem. We’re going to end up preaching to the choir until it’s far too late and these servers start getting compromised.”

Jacob Warner, Director of IT, Xcape, Inc. https://www.linkedin.com/in/jacob-warner-n1377

“Boring infrastructure with credential-free remote code execution and self-erasing payloads is how a print server becomes a domain-wide incident. When an unauthenticated request becomes SYSTEM on your print server, the resulting administrative compromise transforms routine utility services into elevated beachheads for lateral movement across enterprise environments. Because the attacker cleans up after themselves, security teams must patch now and assume the logs will not tell them if they were late to respond. Traditional vulnerability scanners often miss active zero-day exploitation until vendor signatures catch up. Defenders should patch or isolate today, close all Internet exposure, and image affected machines before remediation, as the attacker’s cleanup routine may have already deleted the logs that would have confirmed exposure.

“Unauthenticated remote code execution on print management software grants immediate elevated privileges, escalating utility software into a full domain threat. Self-erasing payloads and automated log deletion mean security teams cannot rely solely on post-incident forensic artifacts to detect compromise. Immediate containment requires closing all Internet exposure, imaging affected application servers prior to remediation, and applying vendor patches immediately.

“Boring utility servers make the best targets because nobody expects the print spooler to hand over domain administrator rights.”

Seemant Sehgal, Founder & CEO, BreachLock https://www.linkedin.com/in/s-sehgal

“Pre-authentication RCE means the attacker needs nothing from you. No credentials, no foothold, no prior access, before they own the application and can run arbitrary Java on your infrastructure. The first question every team should be answering right now is whether their PaperCut instance is reachable from the internet, because if it is, that answer is more urgent than any patch timeline. Vulnerability scanners will tell you the CVE exists, but they will not tell you whether an attacker already walked through it and what the impact would be if they did.”

Denis Calderon, Principal & CTO, Suzu Labs https://www.linkedin.com/in/deniscalderone

“PaperCut’s Application Server runs as SYSTEM on Windows, manages configurations for every endpoint in the org, and has a web-accessible console that is often exposed to the Internet. It’s “just printing”, but in this case, its important to treat it like any other management plane that holds implicit trust within your network.

“I ran a Shodan query this morning and found over 1,000 of these servers exposed to the public internet on their default management ports. A lot of them look like schools. That makes sense. PaperCut is heavily deployed in education for managing student print quotas, and students need to access the system from their own devices, so the web interface ends up internet-facing almost by necessity. The first confirmed victim to report this exploitation to PaperCut was a university. These servers are findable in seconds, they require zero credentials to exploit, and the attacker gets SYSTEM-level code execution. Unfortunately, even a well managed vulnerability scanning program wouldn’t have flagged this since it was an 0day, and you can’t see vulnerabilities that haven’t been discovered yet. That’s the fundamental limitation. The exposure itself was the risk, long before anyone knew the specific flaw.

“So, needless to say, get the PaperCut Emergency Patch Release 2 implemented immediately.  It covers v24, v25, and v26. I wish I could advise a holistic architectural fix like removing the admin interface off the internet, but it’s unclear from the current reporting whether that alone would have stopped this. The auth bypass operates below the URL routing layer, so even user-facing endpoints may have been sufficient for the attacker to reach the vulnerable components. What is clear is that a restrictive egress policy would have stopped this. Huntress’s proven exploit chain required SMB to traverse outbound from the victim to an attacker-controlled share. That can and should be controlled and stopped at the perimeter. If your PaperCut server can initiate outbound SMB to the internet, fix that today. And then hunt. Keep in mind that this malware deletes server.log, derby.log, and its own class files after execution. If your server was internet-exposed yesterday, patch or no patch, you need to be hunting today. Preserve those logs before you restart anything, look for the indicators Huntress published, and assume compromise until you can prove otherwise.”

If you use PaperCut, consider this a today problem. Patch now and keep watching this advisory as I am sure that this is not the last that we’ve heard of this issue.

Leave a Reply

Discover more from The IT Nerd

Subscribe now to keep reading and get access to the full archive.

Continue reading