Arbitrary File Deletion in PaperCut NG/MF Web Print
CVE-2024-3037

7.8HIGH

Key Information:

Vendor
Papercut
Vendor
CVE Published:
14 May 2024

Summary

An arbitrary file deletion vulnerability exists in PaperCut NG/MF impacting Windows servers with Web Print enabled. Exploitation requires the attacker to secure local login access to the vulnerable server and execute low-privilege code. This vulnerability might be mitigated in standard configurations where only Administrators are permitted local login. However, environments allowing non-administrative users local access face potential risks. The CVE has been differentiated into two distinct identifiers, reflecting an environment where local login permissions could lead to inadvertent exposure.

Affected Version(s)

PaperCut NG, PaperCut MF Windows 0 < 23.0.9

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

Credit

Nicholas Zubrisky (@NZubrisky)
Michael DePlante(@izobashi) of Trend Micro's ZDI
.