PT-2023-7173 · Papercut · Papercut Ng+1

Amol Dosanjh

+2

·

Publicado

2023-11-13

·

Atualizado

2024-09-26

·

CVE-2023-6006

CVSS v3.1

7.8

Alta

VetorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions PaperCut NG (affected versions not specified) PaperCut MF (affected versions not specified)
Description The issue is related to insufficient authentication procedures in PaperCut NG and PaperCut MF, allowing local attackers to escalate privileges. An attacker must have local write access to the C Drive, and Print Archiving must be enabled or the system must be misconfigured. The vulnerability exists within the pc-pdl-to-image process, which loads an executable from an unsecured location, enabling attackers to execute arbitrary code in the context of SYSTEM.
Recommendations For PaperCut NG, ensure Print Archiving is enabled and configured according to the recommended setup procedure to mitigate the risk. As a temporary workaround, consider restricting access to the pc-pdl-to-image process until a patch is available. Avoid granting local login access to standard network users on the host server to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Improper Privilege Management

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2023-08200
CVE-2023-6006
ZDI-23-1798

Produtos afetados

Papercut Mf
Papercut Ng