CVE-2024-8404
CVSS 3.1 Score 7.8 of 10 (high)
Details
Summary
CVE-2024-8404 is a newly identified vulnerability in PaperCut NG/MF, specifically affecting Windows servers with Web Print enabled. An attacker must first gain local login access to the Windows Server and execute low-privilege code to exploit this arbitrary file deletion vulnerability. While the default Windows Server configuration restricts local login access to Administrators, this vulnerability poses a risk for organizations that grant such access to non-administrative users. Importantly, CVE-2024-8404 was previously associated with CVE-2024-3037 but has since been split into a separate vulnerability.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- PaperCut MF
- PaperCut NG
Affected Vendors
- PaperCut Software Pty Ltd
- Papercut