logo

Critical Vulnerabilities in PaperCut Print Management Software

ID: 93d9d845-ecec-559d-b1d0-5570e556869f

STIX ID: report--93d9d845-ecec-559d-b1d0-5570e556869f

Feed Name: Huntress Blog

Threat Score
80/100

Date Published: 2024-02-03

Date Updated: 2026-04-28

...
...

Huntress documents active exploitation of PaperCut MF/NG zero-day authentication-bypass vulnerabilities (CVE-2023-27350 / CVE-2023-27351) that allow unauthenticated RCE as NT AUTHORITY\SYSTEM; observed April 16–22, 2023, activity includes installation of legitimate RMM agents, a Truebot DLL, and deployment of a Monero miner across numerous organizations. The report provides technical analysis of the vulnerability and exploitation path, IoCs (file hashes, domains, IPs), detection guidance (including a Sigma rule), and mitigation recommendations such as patching or blocking the management port.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.