ZDI-25-420: PaperCut NG web-print-hot-folder Link Following Local Privilege Escalation Vulnerability
This vulnerability allows local attackers to escalate privileges on affected installations of PaperCut NG. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2024-8404.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-25-420?
The vulnerability ZDI-25-420 has been assigned a CVSS rating of 7.8, indicating high severity.
How do I fix ZDI-25-420?
To fix ZDI-25-420, update PaperCut NG to the latest version provided by the vendor.
Who is affected by ZDI-25-420?
Local attackers with low-privileged code execution capabilities on systems running PaperCut NG are affected by ZDI-25-420.
What type of vulnerability is ZDI-25-420?
ZDI-25-420 is a privilege escalation vulnerability that allows attackers to gain elevated permissions on vulnerable systems.
Is ZDI-25-420 being actively exploited?
As of now, there is no public information indicating that ZDI-25-420 is being actively exploited in the wild.