Critical RCE Vulnerability in PaperCut Servers: Hackers Exploit and Deploy Malware
The PaperCut printing management software is widely used by businesses and educational institutions around the world. Unfortunately, security researchers have discovered a critical remote code execution (RCE) vulnerability in PaperCut that could allow attackers to take control of a server running the software. Even worse, hackers are actively exploiting this vulnerability to launch attacks on vulnerable systems. The RCE vulnerability, tracked as CVE-2021-34527, is caused by a flaw in the way PaperCut handles user input. By sending specially crafted data to a vulnerable server, an attacker could execute arbitrary code with system-level privileges. This could allow the attacker to take complete control of the server and access sensitive data. According to security researchers, hackers have already begun exploiting this vulnerability in the wild. In one reported incident, attackers used the RCE bug in PaperCut to deploy the Cobalt Strike malware on a victim's system. Cobalt Strike is ...