ZDI-24-1038: PaperCut NG pc-web-print Link Following Local Privilege Escalation Vulnerability
This vulnerability allows local attackers to escalate privileges on affected installations of PaperCut NG Server. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2024-3037.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-24-1038?
The ZDI-24-1038 vulnerability has been assigned a CVSS rating indicating a significant risk of privilege escalation.
How do I fix ZDI-24-1038?
To address the ZDI-24-1038 vulnerability, update PaperCut NG Server to the latest patched version provided by the vendor.
What type of attack does ZDI-24-1038 enable?
ZDI-24-1038 enables local attackers to escalate privileges on affected installations of PaperCut NG Server.
What must an attacker do to exploit ZDI-24-1038?
An attacker must first obtain the ability to execute low-privileged code on the target system to exploit ZDI-24-1038.
Which software is affected by ZDI-24-1038?
The ZDI-24-1038 vulnerability affects installations of PaperCut NG Server.