CVE-2024-4712 HIGH

CVE-2024-4712: Arbitrary File Creation in PaperCut NG/MF Web Print Image Handler

Vendor Papercut
Product PaperCut NG, PaperCut MF
Weakness CWE-77
Published May 14, 2024
Last update September 26, 2024

CVSS base score

7.8/10
Attack vector Local
Attack complexity Low
Privileges required Low
User interaction None
Confidentiality High
Integrity High

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

What the vulnerability does

01Description

An arbitrary file creation vulnerability exists in PaperCut NG/MF that only affects Windows servers with Web Print enabled. This specific flaw exists within the image-handler process, which can incorrectly create files that don’t exist when a maliciously formed payload is provided. This can lead to local privilege escalation. Note: This CVE has been split into two (CVE-2024-4712 and CVE-2024-8405) and it’s been rescored with a "Privileges Required (PR)" rating of low, and “Attack Complexity (AC)” rating of low, reflecting the worst-case scenario where an Administrator has granted local login access to standard network users on the host server.

Key dates

02Disclosure timeline

May 14, 2024 CVE published
September 26, 2024 Record updated