Improper access control in PaperCut NG and PaperCut MF - CVE-2024-3037
Published: June 17, 2024 / Updated: August 5, 2024
Vulnerability identifier: #VU92182
CSH Severity: Low
CVSS v4: 4.6 [CVSS:4.0/AV:L/AC:L/AT:N/PR:H/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2024-3037
CWE-ID: CWE-284
Exploitation vector: Local access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a local user to delete arbitrary files.
The vulnerability exists due to improper access restrictions. A local user member of a domain admin group can delete arbitrary files on the system.
The vulnerability affects Windows servers with Web Print enabled.
Affected software
PaperCut NG
PaperCut MF
PaperCut MF
How to mitigate CVE-2024-3037
Install updates from vendor's website.
PaperCut NG - update to 23.0.9
PaperCut MF - update to 23.0.9
PaperCut MF - update to 23.0.9