PaperCut has disclosed a zero-day attack targeting its PaperCut NG and PaperCut MF print management products, after a university security team alerted the company to an intrusion. The company confirmed customer incidents in an urgent advisory issued this week and released an emergency patch, while urging customers to remove the products' web interfaces from the public internet.
PaperCut has revealed that its PaperCut NG and PaperCut MF print management products are under attack through a previously unknown vulnerability, after a university's security team alerted the company to intrusions. The company said it analyzed information from the university and identified the flaw, and confirmed "customer incidents" in an urgent security advisory issued Thursday.
The software manages access to printers, tracks usage and enables printing from a range of client devices. According to The Register, the advisory is unusually silent on the nature of the flaw and the risk it poses. Indicators of compromise listed by PaperCut include altered log files and alerts from intrusion detection software, endpoint security tools and network monitoring packages — suggesting the web interface may give attackers a path deeper into customers' networks.
"We are aware of confirmed customer incidents and are treating this matter with the highest priority," PaperCut stated in the advisory.
The company has produced an emergency patch but cautioned that it is not an official release. "We have not gone through our usual release process," the company said in an FAQ. "This is an emergency patch for customers with public-facing PaperCut servers who are unable to take other mitigating action."
Customers can instead mitigate by moving PaperCut servers' web interfaces off the public internet, allowing access only from trusted internal IP addresses. PaperCut said it is working on a better fix and will advise users when it is ready. The Register noted that many customers may prefer to take servers offline rather than run unvalidated emergency software, and that finding a change window to apply the patch is a practical hurdle.
Analysis
Why This Matters
- Organizations running PaperCut NG or MF with internet-exposed web interfaces face active attacks; the company confirms real customer incidents, not a theoretical risk.
- The intrusion indicators suggest attackers may use the flaw to move deeper into internal networks, raising the stakes beyond printer access.
- Mitigation is disruptive: affected organizations must either restrict access to trusted IPs or take print servers offline until a proper fix arrives.
Background
PaperCut NG and PaperCut MF are print management products that control access to printers, track usage and support printing from many client devices. As with much enterprise software, their web interfaces are designed for administration and can become an attack surface if exposed to the public internet. A zero-day attack exploits a vulnerability before the vendor has issued a patch; in such cases vendors often withhold technical details to avoid giving other attackers a roadmap, which can leave customers uncertain about their exposure while they wait for a fix.
Key Perspectives
PaperCut: The company says it is treating the matter with the highest priority, has released an emergency patch for affected customers and is working on a proper fix. Its guidance emphasizes removing public-facing web interfaces as the primary mitigation.
Affected customers: The incidents were first flagged by a university's security team, indicating that defense-in-depth monitoring — endpoint tools, intrusion detection and network monitoring — is what surfaces the attacks. Customers running public-facing servers face a choice between an unvalidated emergency patch and taking servers offline.
Critics/Skeptics: The Register observes that applying unvalidated emergency software is an unappealing option for many organizations, and that the advisory's silence on the flaw leaves customers unable to assess the actual risk. Timing a patch window against an active zero-day is also a practical challenge.
What to Watch
- A permanent, formally released patch from PaperCut, which the company says it is working on.
- Any further disclosure of the vulnerability's technical details or indicators of compromise.
- Whether the number of confirmed customer incidents grows or is contained by the recommended mitigations.