PaperCut Print Server Exploits Lead to Domain Controller Breach

Hackers Turned a PaperCut Print Server Into a Path to the Domain Controller

Threat actors successfully exploited two zero-day vulnerabilities in PaperCut MF print servers to establish initial access into enterprise networks, then pivoted laterally to compromise Active Directory and domain controllers. The attack chain demonstrates how adversaries target overlooked peripheral systems—in this case, print management software—to reach crown jewel assets. Organizations running PaperCut MF should immediately apply available patches, segment these systems from critical infrastructure, and implement enhanced monitoring for anomalous authentication patterns targeting domain controllers.

Introduction

Print servers rarely top the list of security concerns for most organizations. Yet attackers increasingly recognize that these ubiquitous, often-neglected systems provide an ideal beachhead for network infiltration. In a sophisticated campaign, threat actors exploited zero-day vulnerabilities in PaperCut MF print management software to gain initial access, then methodically moved laterally through the network until reaching Active Directory domain controllers—the keys to the kingdom in Windows environments.

This attack pattern underscores a critical gap in enterprise security postures: peripheral systems with deep network access and privileged credentials frequently operate outside the security hardening and monitoring applied to obvious targets like servers and workstations. Print management software, with its requirement for broad network visibility and often elevated permissions, presents an especially attractive target.

Background & Context

PaperCut MF is a widely deployed print management solution used by educational institutions, healthcare organizations, government agencies, and enterprises globally. The software typically runs on dedicated servers with network connectivity to print devices, user authentication systems, and often integrates directly with Active Directory for user management and authentication.

This integration, while operationally necessary, creates inherent security risks. PaperCut servers typically maintain service accounts with domain credentials, require network access across multiple VLANs to communicate with printers, and process user authentication requests—placing them at a privileged position within network architecture.

Zero-day vulnerabilities in such systems are particularly dangerous because they lack signatures or known indicators of compromise. When attackers identify these flaws before vendors, they gain a window of opportunity to exploit thousands of installations before patches become available.

The targeting of print infrastructure follows established patterns observed in previous campaigns. Attackers understand that security teams focus resources on protecting databases, web applications, and endpoints while neglecting supporting infrastructure. This asymmetry creates exploitable gaps.

Technical Breakdown

The attack chain involved multiple stages, beginning with exploitation of the zero-day vulnerabilities in PaperCut MF to achieve remote code execution on the print server.

Initial Access Phase:

The attackers exploited authentication bypass and path traversal vulnerabilities that allowed unauthenticated remote code execution. The specific CVEs were assigned after discovery:

CVE-2023-27350: Path traversal vulnerability (CVSS 9.8)
CVE-2023-27351: Authentication bypass (CVSS 8.2)

These vulnerabilities exist in the web application component of PaperCut MF, which typically listens on ports 9191 (HTTP) and 9192 (HTTPS). By chaining these vulnerabilities, attackers could upload malicious files and execute arbitrary code without valid credentials.

Privilege Escalation:

Once code execution was achieved, attackers leveraged the context in which PaperCut services run. In many deployments, PaperCut operates under accounts with excessive privileges to facilitate printer management and Active Directory integration. The attackers extracted credentials from memory and configuration files.

C:\Program Files\PaperCut MF\server\data\conf\
HKLM\SOFTWARE\PaperCut\

Lateral Movement:

With domain credentials in hand, the attackers performed reconnaissance to map the Active Directory environment:

# Commands observed in post-exploitation:
nltest /domain_trusts
net group "Domain Admins" /domain
Get-ADComputer -Filter  -Property 

The print server’s legitimate network access allowed this reconnaissance to blend with normal traffic. Attackers then used standard Windows administration tools to move laterally toward domain controllers.

Domain Controller Compromise:

Final stage attacks against domain controllers involved credential dumping, creating persistent backdoors, and establishing additional access mechanisms. Tools like Mimikatz and custom malware variants were deployed to extract the NTDS.dit database, effectively compromising every domain account.

Impact & Risk Assessment

The consequences of this attack pattern extend far beyond compromised print services. Once attackers gain domain controller access, they achieve complete control over the Windows environment.

Immediate Impacts:

  • Complete credential compromise affecting all domain users
  • Ability to create persistent backdoor accounts with administrative privileges
  • Access to sensitive data across all domain-joined systems
  • Potential for ransomware deployment affecting entire infrastructure
  • Loss of audit trail integrity through event log manipulation

Business Risks:

Organizations facing this attack scenario confront severe operational and financial consequences. Recovery from domain-level compromise requires extensive remediation including full Active Directory rebuilding, comprehensive password resets, and validation of system integrity across the entire environment.

The average cost of remediation ranges from hundreds of thousands to millions of dollars, depending on organization size. Downtime during recovery can extend for weeks, disrupting normal operations.

Affected Versions:

PaperCut MF and NG versions 8.0 through 20.1.6, 21.x through 21.2.10, and 22.x through 22.0.8 were confirmed vulnerable prior to patching.

Vendor Response

PaperCut released emergency patches addressing both vulnerabilities within days of discovery. The vendor issued security bulletins strongly urging immediate patching and provided detailed upgrade instructions.

PaperCut’s response included:

  • Security patches for all affected versions
  • Detailed security bulletin (Release ID: 221222) with technical details
  • Workarounds for organizations unable to patch immediately
  • Direct notification to registered customers
  • Cooperation with security researchers and incident responders

The vendor established a dedicated security response page and committed to enhanced security testing for future releases. They also recommended restricting network exposure of PaperCut servers as a defense-in-depth measure.

Mitigations & Workarounds

Organizations must take immediate action to protect PaperCut deployments and contain potential compromises.

Immediate Actions:

  • Apply patches immediately – Update to PaperCut MF/NG version 20.1.7, 21.2.11, 22.0.9 or later
  • Restrict network access – Block internet access to PaperCut servers; implement firewall rules limiting access to ports 9191/9192
  • Audit service accounts – Review and restrict privileges of PaperCut service accounts; implement least-privilege principles
  • Check for compromise indicators – Review logs for suspicious authentication patterns, unexpected file modifications, or unusual network connections

Network Segmentation:

# Firewall rule example - restrict PaperCut access:
Allow: Internal_Print_VLAN -> PaperCut_Server:9191-9192
Allow: Admin_VLAN -> PaperCut_Server:9191-9192  
Deny: ALL -> PaperCut_Server:9191-9192

Temporary Workarounds:

For organizations unable to patch immediately, disable the external device integration feature and restrict web interface access through firewall rules. This reduces attack surface while planning patching windows.

Detection & Monitoring

Identifying active exploitation or post-compromise activity requires monitoring multiple indicators across different security layers.

Network Indicators:

# Suspicious connections to monitor:
  • External connections to ports 9191/9192
  • Unusual authentication attempts to PaperCut web interface
  • Lateral movement from print server to domain controllers
  • Data exfiltration from print server systems

Host-Based Indicators:

Monitor for unexpected processes, file modifications in PaperCut directories, credential access attempts, and suspicious PowerShell execution:

# Detection logic example:
Get-WinEvent -LogName Security | Where-Object {
    $_.Id -eq 4624 -and 
    $_.Properties[8].Value -eq "10" -and
    $_.Properties[5].Value -match "PaperCut"
}

Active Directory Monitoring:

Implement enhanced monitoring for domain controller access from unexpected sources, unusual administrative account creation, and attempts to access NTDS.dit or LSASS memory.

Deploy SIEM rules correlating print server authentication with subsequent domain controller access—this pattern rarely occurs in legitimate operations.

Best Practices

This incident highlights fundamental security principles that organizations must implement across all infrastructure.

Asset Management:

Maintain comprehensive inventories of all internet-accessible systems, including peripheral infrastructure like print servers. Many organizations lack visibility into these systems, creating blind spots attackers exploit.

Principle of Least Privilege:

Service accounts for print management and similar functions should operate with minimum necessary permissions. PaperCut doesn’t require Domain Admin rights—implementing proper delegation reduces blast radius.

Network Segmentation:

Peripheral systems should operate in isolated network segments with strictly controlled access paths to critical infrastructure. Print servers should not have direct network access to domain controllers.

Patch Management:

Establish processes for rapidly deploying emergency patches to all systems, not just obvious targets. Include peripheral infrastructure in patch management workflows with defined SLAs.

Defense in Depth:

Implement multiple security layers so single vulnerabilities don’t provide complete compromise. Endpoint detection, network monitoring, and identity protection should all play roles in defense strategy.

Key Takeaways

  • Print servers and similar peripheral systems present serious security risks when overlooked in hardening and monitoring efforts
  • Zero-day exploitation of overlooked systems provides attackers with low-resistance initial access paths to critical infrastructure
  • Integration with Active Directory makes any compromised system a potential path to domain controllers
  • Immediate patching, network segmentation, and privilege reduction are essential protective measures
  • Organizations must expand security focus beyond obvious targets to include all systems with network access and credentials

References

  • PaperCut Security Bulletin: CVE-2023-27350 and CVE-2023-27351
  • CISA Alert: Known Exploited Vulnerabilities Catalog
  • Microsoft Security: Best Practices for Securing Active Directory
  • MITRE ATT&CK: T1210 (Exploitation of Remote Services), T1003 (OS Credential Dumping)

Stay updated at https://cydhaal.com — Your Daily Dose of Cyber Intelligence.
📧 Subscribe to our newsletter at https://cydhaal.com/newsletter/


Leave a Reply

Your email address will not be published. Required fields are marked *

💬 Join WhatsApp Channel 📲 Cydhaal App