Skip to content
See the World Through Science

PaperCut Issues an Emergency Patch, Saying Customers Are Already Under Attack

AI & Technology

Republish this story

Our work is licensed under Creative Commons BY-NC 4.0. You may republish this piece for free — with credit to ALLATRA Media and a link to the original, unedited beyond length trims, and not for commercial use.

Read the full license

Two large office multifunction laser printers standing side by side
Office multifunction printers of the kind a print-management server such as PaperCut NG or MF administers (illustrative)."Canon imageRUNNER ADVANCE DX C5860 Color Laser Multifunction Printer & Canon imageRUNNER ADVANCE DX C7770 Color Laser Multifunction Printer" by Dinkun Chen, via wikimedia, CC-BY-SA-4.0 · CC-BY-SA-4.0

PaperCut released an emergency patch for its PaperCut NG and PaperCut MF print management servers early on Aug. 28, hours after the company said it was investigating active exploitation of a vulnerability in both products.

The company's security bulletin, first published Aug. 27, says its security response team "is investigating active exploitation of a vulnerability affecting PaperCut NG and PaperCut MF" and that the company is "aware of confirmed customer incidents."

According to the bulletin's change log, the patch was published at 2:10 a.m. AEST on Aug. 28 and covers versions 25 and 26 of both products. PaperCut says it did not follow its normal procedure. Asked in its own FAQ whether this is an official release, the company answers: "No. We have not gone through our usual release process." Builds for version 24 are "still in progress," per the same FAQ.

The advisory applies to all versions of PaperCut NG and PaperCut MF, the company says. It tells administrators whose servers are reachable from the public internet to restrict web access to trusted addresses immediately, and to do so "even if you have not observed suspicious activity."

The bulletin carries no CVE number, the standard public identifier given to a security flaw, and no severity score or technical description. PaperCut says it will update the page "as verified information becomes available, including indicators of compromise and remediation guidance," and that the absence of the preliminary indicators it lists is not confirmation that a system has not been affected.

The company says information supplied by a university customer's security team and its incident response team let PaperCut reproduce the vulnerability in its own code.

PaperCut also says the patched builds change one feature. Sites that look up card or ID numbers from an external database can no longer use certain database query commands in those lookups, and the company tells those customers to read its FAQ before installing.

Sources

Spot an error?

Spot an error?

Report an error

Spotted a mistake on this page? Tell us what's wrong and our editors will take a look.

What kind of problem?

Only if you'd like us to be able to follow up. We won't use it for anything else.

We correct mistakes openly. Select any text to flag it. Fixes are logged under our Corrections Policy.

Report an error

Reporting on

PaperCut Issues an Emergency Patch, Saying Customers Are Already Under Attack

What kind of problem?

Only if you'd like us to be able to follow up. We won't use it for anything else.

We read every report. Corrections are logged publicly.