Critical Vulnerabilities in PaperCut Print Management Software
ID: 93d9d845-ecec-559d-b1d0-5570e556869f
STIX ID: report--93d9d845-ecec-559d-b1d0-5570e556869f
Feed Name: Huntress Blog
Huntress documents active exploitation of PaperCut MF/NG zero-day authentication-bypass vulnerabilities (CVE-2023-27350 / CVE-2023-27351) that allow unauthenticated RCE as NT AUTHORITY\SYSTEM; observed April 16–22, 2023, activity includes installation of legitimate RMM agents, a Truebot DLL, and deployment of a Monero miner across numerous organizations. The report provides technical analysis of the vulnerability and exploitation path, IoCs (file hashes, domains, IPs), detection guidance (including a Sigma rule), and mitigation recommendations such as patching or blocking the management port.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
