Zero‑Day Exploitation of PaperCut NG/MF Print‑Management Software Affects All Versions
What Happened — PaperCut disclosed that a previously unknown vulnerability in every version of its PaperCut NG and PaperCut MF print‑management platforms is being actively exploited in zero‑day attacks. The flaw is leveraged against Internet‑exposed Application Servers, and the vendor has issued emergency patches and mitigation guidance.
Why It Matters for Compliance & Audit Readiness
- The incident illustrates a classic control‑gap scenario: public‑facing services without strict network segmentation or IP‑based allow‑lists. SOC 2 requires documented access‑control policies and continuous monitoring to prove that such gaps are closed.
- Evidence of rapid patch deployment, firewall rule changes, and log‑review activities can serve as audit‑ready artifacts for the Security (CC6.1) and Availability (CC7.1) principles.
- Verisq’s Control Mapping capability can automatically map the remediation steps (patches, firewall rules, IOCs) to the relevant SOC 2 controls and collect continuous evidence for the Trust Center.
Who Is Affected — Organizations that run PaperCut NG/MF on on‑premise or cloud‑hosted servers, spanning education, healthcare, finance, and large enterprises that expose the web interface to the Internet.
Recommended Actions
- Immediately restrict access to PaperCut web interfaces to trusted IP ranges via firewall or network‑access controls.
- Deploy the emergency patches released by PaperCut on all affected servers.
- Enable continuous log monitoring for the listed IOCs (pc‑app.exe activity, server.log anomalies) and retain evidence for audit purposes.
- Map the remediation steps to SOC 2 controls using a control‑mapping solution and capture the evidence in a centralized Trust Center.
Source: BleepingComputer – PaperCut warns of NG, MF flaw exploited in zero‑day attacks
Technical Notes
- Vulnerability type: unknown‑detail zero‑day affecting all PaperCut NG/MF versions; no CVE identifier disclosed.
- Attack vector: exploitation of a server‑side flaw via the publicly reachable PaperCut Application Server.
- Indicators of compromise: suspicious activity from
pc-app.exe, modified or missingserver.logentries, errors such as “ERROR No suitable driver found for jdbc:no:x” and “ERROR DatabaseUtils - Database error looking up cardID: VALUES CAST”. - No public information on attacker attribution or data exfiltration at this time.
Source: same as above