PaperCut Addresses Exploited Vulnerabilities with Second Emergency Patch
PaperCut has released a second emergency security update addressing two critical vulnerabilities in its PaperCut NG and MF print management software. This comes after threat actors discovered multiple methods to bypass the initial patches deployed last month. The advisory urges all customers to update immediately, as active exploitation of these flaws is ongoing.
Vulnerability Details and Exploitation
The vulnerabilities, identified as CVE-2023-27350 and CVE-2023-27351, are critical flaws that allow for unauthenticated remote code execution (RCE). Initially, PaperCut released patches on March 16th, but researchers quickly found that these fixes were insufficient. Attackers could still exploit the software through various means, including but not limited to the initial attack vectors, by crafting malicious requests that bypassed the implemented security checks.
The bypass methods exploited the software's handling of specific web requests. For instance, by manipulating the `id` parameter in certain URLs, attackers could trick the server into executing arbitrary commands. This bypass was reportedly effective even on systems that had applied the first set of patches. The ease with which these vulnerabilities could be exploited, coupled with the discovery of bypass techniques, made the situation particularly urgent for PaperCut's user base.

Impact and Affected Versions
PaperCut NG and PaperCut MF are widely used print management solutions in enterprise environments. They help organizations track, manage, and secure print, copy, scan, and fax activity. Given their prevalence, any unpatched vulnerability poses a significant risk to corporate networks. Successful exploitation could lead to full system compromise, data breaches, ransomware deployment, or lateral movement within a network.
The affected versions include PaperCut NG and PaperCut MF versions prior to 22.0.90.2 (for the initial fix) and now specifically requiring update to versions 22.1.3 and 22.0.90.6 or later for the second, more robust fix. Customers running older, unsupported versions are also at risk and are strongly advised to upgrade to a supported version and apply the latest patches.
Timeline and Disclosure
PaperCut first acknowledged the vulnerabilities on March 16, 2023, releasing an initial patch shortly thereafter. However, the discovery of bypass techniques by security researchers, including those from Rapid7 and independently by researchers who reported to PaperCut, necessitated a swift response. The second emergency patch was released on April 13, 2023, indicating a rapid development and testing cycle to address the newly discovered exploitation vectors.
The situation highlights the cat-and-mouse game often played in cybersecurity. As vendors release patches, attackers and researchers actively seek ways to circumvent them. This underscores the importance of not only applying patches promptly but also of continuous monitoring for new threats and vulnerabilities. PaperCut's quick response to the bypass discovery demonstrates a commitment to user security, but also the inherent challenges in securing complex software systems against determined adversaries.
Mitigation and Recommendations
PaperCut strongly advises all users of PaperCut NG and PaperCut MF to update to the latest version immediately. The company has provided specific build numbers for the patched versions:
- PaperCut NG: 22.1.3 or later
- PaperCut MF: 22.0.90.6 or later
For organizations unable to update immediately, PaperCut recommends implementing network-level firewall rules to block incoming traffic to the PaperCut NG/MF server on ports 9191 and 5080, although this is considered a temporary measure and not a substitute for patching.
The security implications of these vulnerabilities are severe. The ability for unauthenticated attackers to execute arbitrary code means that any internet-facing or internally accessible PaperCut server is a prime target. The bypass of initial patches means that organizations that believed they were secure after the first update are now vulnerable again. This second patch is critical for closing the loopholes that allowed attackers to persist their exploits.
Broader Implications for Software Security
This incident serves as a stark reminder for both software vendors and users. For vendors, it emphasizes the need for rigorous testing of patches, anticipating potential bypass techniques, and having robust incident response plans. It's not enough to fix a vulnerability; the fix itself must be resilient.
For users, particularly IT and security professionals managing these systems, it highlights the imperative of staying vigilant. Relying solely on vendor advisories without independent verification or continuous monitoring can leave organizations exposed. The rapid discovery of bypasses indicates that a multi-layered security approach, including network segmentation, intrusion detection, and prompt patching, remains the most effective defense. If you run PaperCut NG or MF, consider this your urgent call to action. The risk of not updating is a compromised print infrastructure, which can be a gateway to much larger network breaches.
