Hospitals urged to lock down PaperCut print servers under attack

PaperCut is rushing out emergency patches after attackers began exploiting an unpatched flaw in its widely used print management software.

MedRisk Staff
By
2 Min Read

Print management vendor PaperCut warned customers on August 27 that attackers are actively exploiting an unpatched vulnerability in its PaperCut NG and PaperCut MF software, with confirmed customer incidents already reported. The company pushed out emergency patches hours after its first advisory, covering every currently supported version. No CVE identifier has been assigned yet.

PaperCut NG and MF are among the most common print management platforms in hospitals and clinics, where they control printing of patient records, wristbands, and lab labels from servers and multifunction copiers. The vendor’s bulletin urges organizations whose Application Server, the single brain of each deployment, is reachable from the public internet to restrict web access to trusted IP addresses immediately.

PaperCut also published indicators of compromise for defenders: alerts tied to the pc-app.exe process, missing or truncated server.log files, and specific database error strings in the log. The vendor credited a university customer’s security team and digital forensics firm with helping it reproduce the flaw.

Healthcare organizations have been burned by this software before. In 2023, Clop and LockBit affiliates exploited two PaperCut remote code execution flaws, CVE-2023-27350 and CVE-2023-27351, and print servers became a common ransomware entry point across sectors, including hospitals.

Security teams should patch immediately, confirm the Application Server is not internet-exposed, review logs for the listed indicators, and treat any suspicious pc-app.exe activity as a potential intrusion.

Share This Article