PaperCut NG < 23.0.9 Multiple Vulnerabilities

high Nessus Plugin ID 209140

Synopsis

PaperCut NG installed on remote Windows host is affected by a multiple vulnerabilities

Description

The version of PaperCut NG installed on the remote Windows host is affected by multiple vulnerabilities, as follows:

- An arbitrary file deletion vulnerability exists in PaperCut NG/MF, specifically affecting Windows servers with Web Print enabled. To exploit this vulnerability, an attacker must first obtain local login access to the Windows Server hosting PaperCut NG/MF and be capable of executing low-privilege code directly on the server. The attacker can leverage this attack by creating a symbolic link, and use this service to delete the file the link is pointing to. (CVE-2024-3037)

- This vulnerability could potentially allow the creation of files in specific locations used by the Web Print service. This vulnerability only applies to PaperCut NG/MF Windows servers with the PaperCut Web Print Server service enabled and uses the image-handler process, which can incorrectly create files that don’t exist when a maliciously formed payload is provided. (CVE-2024-4712)

- CVE-2024-8404 and CVE-2024-8405 have been split to allow the researchers (Trend Micro ZDI) to attribute two instances of the same vulnerability type to different reporters.

Note that Nessus has not tested for these issues but has instead relied only on the application's self-reported version number.

Solution

Upgrade to PaperCut NG version 23.0.9 or later.

See Also

https://www.papercut.com/kb/Main/Security-Bulletin-May-2024

Plugin Details

Severity: High

ID: 209140

File Name: papercut_ng_23_0_9.nasl

Version: 1.1

Type: local

Agent: windows

Family: Windows

Published: 10/16/2024

Updated: 10/16/2024

Supported Sensors: Nessus Agent, Nessus

Risk Information

VPR

Risk Factor: Medium

Score: 6.7

CVSS v2

Risk Factor: Medium

Base Score: 6.8

Vector: CVSS2#AV:L/AC:L/Au:S/C:C/I:C/A:C

CVSS Score Source: CVE-2024-3037

CVSS v3

Risk Factor: High

Base Score: 7.8

Vector: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Vulnerability Information

CPE: cpe:/a:papercut:papercut_ng

Required KB Items: installed_sw/PaperCut NG, SMB/Registry/Enumerated

Patch Publication Date: 5/14/2024

Vulnerability Publication Date: 5/14/2024

Reference Information

CVE: CVE-2024-3037, CVE-2024-4712, CVE-2024-8404, CVE-2024-8405