LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2023-27350: PaperCut MF/NG Improper Access Control Vulnerability

RBRecent Breaches Vulnerability Intelligence·Apr 21, 2023
Critical⚠ Actively exploited (CISA KEV)Ransomware-linked
Critical
Severity
Active
CISA KEV
Yes
Ransomware use
May 12, 2023
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2023-27350 to its Known Exploited Vulnerabilities catalog on Apr 21, 2023, with a federal patch deadline of May 12, 2023 — meaning attackers are actively using it. If you run the affected software, patch it immediately. Ransomware crews are known to exploit this flaw.

PaperCut MF/NG contains an improper access control vulnerability within the SetupCompleted class that allows authentication bypass and code execution in the context of system.

CVE-2023-27350 is an improper access control vulnerability in PaperCut MF/NG print management software. It resides in the SetupCompleted class and permits an attacker to bypass authentication and achieve code execution in the context of the system account. This matters because successful exploitation can give complete control of the host running PaperCut, and the vulnerability has been used by ransomware operators.

Organizations that rely on PaperCut for print tracking, quotas, or multi-function device management should treat this as a high-priority issue and confirm their exposure against the vendor advisory immediately.

How it works

The weakness is classified as CWE-284 (Improper Access Control). In essence, the software fails to enforce proper authorization checks around a setup-related component. An unauthenticated attacker can reach the SetupCompleted class, bypass normal login requirements, and then execute arbitrary code with system-level privileges on the underlying server.

Because the process runs with elevated rights, the attacker can install malware, create new accounts, move laterally, or deploy ransomware. Exact request formats and payloads are not detailed here; defenders should consult the vendor advisory for the precise attack surface rather than relying on public exploit descriptions.

Am I affected? How to find it in your systems

PaperCut MF and NG are commonly deployed on Windows or Linux servers that act as the central print server or management console for an organization. They are often reachable from internal networks and sometimes from the internet if remote administration or mobile printing features are enabled.

How to remediate

The primary action is to apply the vendor-supplied updates exactly as instructed in the official PaperCut advisory for CVE-2023-27350. CISA likewise directs organizations to apply updates per vendor instructions.

If you can't patch immediately

Until the vendor update can be applied, reduce the attack surface with compensating controls:

If your data may have been exposed

Because this vulnerability has been exploited by ransomware groups, any unpatched PaperCut server that was reachable should be treated as potentially compromised. Conduct a full forensic review of the host, reset credentials that may have been stored or cached by the print server, and examine downstream systems for lateral movement. As a quick additional check, you can run a free exposure scan of your email addresses against known breach data sets to see whether related credentials have already appeared in public dumps.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedPaperCut · MF/NG
WeaknessCWE-284
Added to CISA KEVApr 21, 2023
Federal patch deadlineMay 12, 2023
Known ransomware useYes
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities