HomeCyber BalkansHackers Exploiting Pre-Auth RCE Vulnerability in PaperCut Print Software

Hackers Exploiting Pre-Auth RCE Vulnerability in PaperCut Print Software

Published on

spot_img

Attackers Exploit Critical Vulnerability in PaperCut Print Management Software

Security researchers from Huntress have confirmed that there is an active exploitation of a serious, unauthenticated remote code execution (RCE) vulnerability in PaperCut NG and PaperCut MF, two widely used print management software solutions. This alarming discovery highlights the need for immediate action among organizations that utilize these systems.

The vulnerability poses a significant risk as it allows malicious actors to gain remote access to a PaperCut server’s configuration without requiring any form of login credentials. Once exploited, the flaw enables attackers to execute arbitrary code on the affected system, potentially compromising sensitive data and operational control over the server.

On August 27, PaperCut issued an urgent security advisory to its customers, warning them of the ongoing exploitation of this vulnerability in real-world scenarios. In response, the company released emergency patches for versions 25 and 26 of both products. However, a fix for version 24 is still under development, and the vendor has indicated that all versions of NG and MF may be at risk.

Confirmed Exploitation in Various Environments

Researchers at Huntress reported that they had observed exploitation of the threat in two distinct customer environments. In one instance, attackers executed a base64-encoded command that translated to the commands whoami and ver, which are typically used to identify the compromised account and its operating system version. Remarkably, this attack was conducted in less than two minutes.

In an additional incident, a hex-encoded Java .class file was discovered on the compromised target system, situated within the installation directory of the PaperCut server. When analyzed, this file contained code designed to profile the host operating system, enumerate files on the machine, and write the results to the disk. In an effort to erase their digital footprints, the attackers implemented a self-delete command that targeted not only the malicious file but also server logs.

Moreover, another command observed was decoded to whoami & ver & tasklist, further signifying the attackers’ intent to catalogue the running processes on the targeted servers.

Researchers Successfully Reproduce the Attack Chain

In addition to documenting real-world incidents, Huntress successfully reproduced the full attack chain associated with this vulnerability. Utilizing a stock, unpatched installation of PaperCut NG, the researchers developed a comprehensive proof-of-concept exploit. They demonstrated the ability to trigger code execution without authentication, which enabled a process to run with SYSTEM-level privileges—the highest classification of access on Windows systems—specifically under the PaperCut Application Server process.

Huntress identified that the root cause of this vulnerability was related to the way PaperCut’s authorization checks processed certain crafted requests. This operational flaw allowed the software to be manipulated into checking permissions against an incorrect internal component, opening the door for unauthenticated requests to access sensitive server configuration endpoints that should ordinarily require legitimate login credentials.

Currently, Huntress is collaborating with PaperCut to further analyze this vulnerability and gather additional data regarding its potential ramifications.

Recommended Actions for Affected Organizations

In light of the ongoing threat, both Huntress and PaperCut are compelling organizations that utilize PaperCut NG or MF to implement immediate security measures:

  1. Apply Emergency Patches: Organizations are strongly advised to install PaperCut’s emergency patch for their supported versions without delay.

  2. Restrict Server Access: It is crucial to eliminate any public internet exposure of the PaperCut Application Server. Ideally, access should be limited to trusted IP addresses or secured behind a VPN.

  3. Monitor Outbound Traffic: Organizations should monitor and restrict outbound SMB traffic from the PaperCut server, as Huntress’s proof-of-concept chain utilized this traffic to deliver malicious payloads.

  4. Preserve Forensic Data: Before applying patches or restarting systems, organizations that have had their servers publicly exposed should ensure that server logs and configuration data are preserved for any forthcoming forensic investigation.

  5. Stay Vigilant for Indicators of Compromise: Continuous monitoring for the indicators of compromise specified by PaperCut is critical. These may include missing or truncated server.log files and certain database error messages.

For those who are not able to patch immediately, it is imperative to execute urgency in isolating affected servers from the network.

As the investigation continues, Huntress is committed to keeping the public updated with their findings regarding this vulnerability and the associated exploitation activities. Organizations should remain alert and proactive to mitigate potential threats emanating from this critical security loophole.

Source link

Latest articles

Android 17 Introduces Enhanced Network Security Protections

Google Enhances Network Security in Android 17 In a significant move to bolster user privacy,...

Unit 42 Observes AI Transforming Enterprise Security Practices

Human Oversight in AI-Driven Cybersecurity: Insights from Unit 42 As artificial intelligence (AI) continues to...

The Balance of Healthcare Research Potential and Privacy in the Age of AI

The Impact of AI on Healthcare Research: Navigating Innovation and Privacy Concerns The advancement of...

More like this

Android 17 Introduces Enhanced Network Security Protections

Google Enhances Network Security in Android 17 In a significant move to bolster user privacy,...

Unit 42 Observes AI Transforming Enterprise Security Practices

Human Oversight in AI-Driven Cybersecurity: Insights from Unit 42 As artificial intelligence (AI) continues to...