ZDI-24-1155: PaperCut NG image-handler Directory Traversal Local Privilege Escalation Vulnerability
This vulnerability allows local attackers to escalate privileges on affected installations of PaperCut NG. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2024-4712.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-24-1155?
The severity of ZDI-24-1155 is rated at 7.8 on the CVSS scale, indicating high risk.
How do I fix ZDI-24-1155?
To fix ZDI-24-1155, you should update PaperCut NG to the latest version that addresses this vulnerability.
Who is affected by ZDI-24-1155?
ZDI-24-1155 affects installations of PaperCut NG that are vulnerable to privilege escalation attacks.
What type of attack does ZDI-24-1155 allow?
ZDI-24-1155 allows local attackers to escalate their privileges on the affected system.
What are the prerequisites for exploiting ZDI-24-1155?
An attacker must first gain the ability to execute low-privileged code on the target system to exploit ZDI-24-1155.