First published: Fri Nov 22 2024(Updated: )
PaperCut NG print.script.sandboxed Exposed Dangerous Function Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of PaperCut NG. Authentication is required to exploit this vulnerability. The specific flaw exists within the management of the print.script.sandboxed setting. The issue results from the exposure of a dangerous function. An attacker can leverage this vulnerability to execute code in the context of SYSTEM. Was ZDI-CAN-20965.
Credit: zdi-disclosures@trendmicro.com
Affected Software | Affected Version | How to fix |
---|---|---|
PaperCut NG/MF | ||
PaperCut NG | <22.1.1 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-39470 has a high severity rating due to its ability to allow remote code execution on vulnerable PaperCut NG installations.
To fix CVE-2023-39470, upgrade PaperCut NG to version 22.1.1 or later, where the vulnerability has been addressed.
CVE-2023-39470 enables remote attackers to execute arbitrary code on systems running vulnerable versions of PaperCut NG.
Yes, exploitation of CVE-2023-39470 requires authentication to the affected PaperCut NG installation.
CVE-2023-39470 affects versions of PaperCut NG prior to 22.1.1.