Arbitrary File Creation Vulnerability
CVE-2024-8405
5.5MEDIUM
What is CVE-2024-8405?
An arbitrary file creation flaw in PaperCut NG/MF specifically targets Windows server installations with the Web Print feature enabled. The vulnerability lies in the web-print.exe process, which can be manipulated to create files that shouldn't exist when fed a specially crafted payload. This manipulation can lead to excessive disk space usage, potentially culminating in a Denial of Service (DoS) condition, disrupting the standard operation of the affected server. Organizations using PaperCut on Windows should evaluate their configurations to mitigate potential exploitations.
Affected Version(s)
PaperCut NG, PaperCut MF Windows 0 < 23.0.9