Print management outfit PaperCut is under 0-day attack, and it’s drawing customers’ blood
Nothing smarts like a paper cut, but being attacked after leaving an application’s web interface exposed to the internet might be just as painful.
Such attacks are the risk to which users of PaperCut print management software find themselves exposed today, after the company revealed a university’s security teams alerted it to an attack.
The company analyzed info provided by the university and found a vulnerability in its PaperCut NG and PaperCut MF products, which manage access to printers, track use, and enable printing from myriad client devices.
“We are aware of confirmed customer incidents and are treating this matter with the highest priority,” states an urgent security advisory issued on Thursday.
Unusually, the advisory is silent on the nature of the flaw and the risk it poses.
It looks like the web interface to the company’s products enables access deeper into a user’s networks, because among the indicators of compromise are altered log files, plus alerts from intrusion detection software, endpoint security tools, and network monitoring packages.
The company has cooked up an emergency patch but warns it is not an official release.
“We have not gone through our usual release process,” states an FAQ.
“This is an emergency patch for customers with public-facing PaperCut servers who are unable to take other mitigating action.” Thankfully, those other actions aren’t hard to take: users need to get their PaperCut servers’ web interfaces off the public internet, by allowing access only from trusted internal IP addresses.
Fashioning a potent and rapid response to a zero-day attack is never easy.
Communicating the nature of the problem can be even harder, as discussing the nature of a flaw invites more attackers to take a shot at a stricken product.
PaperCut says it’s working on a better fix and will advise users once it lands.
For now, the company is asking customers to apply its wonky patch or take their servers offline ASAP.
The Register fancies most users will go for the latter fix, as aside from the issue of finding a change window in which to apply a patch, running unvalidated emergency software is not an appetizing approach. ®
5News aggregated this summary from the outlet’s public feed. The full article, with all the context, is on www.theregister.com — the content belongs to The Register.