Bottom line: PaperCut's print management software is vulnerable to exploitation by hackers.
What's happening: A vulnerability in PaperCut NG and MF has been discovered by security researchers at Core Security. The vulnerability, identified as CVE-2022-30114, is a buffer overflow vulnerability that allows attackers to execute arbitrary code. Researchers discovered the vulnerability on January 25, 2022, while testing the software for a separate security project. PaperCut NG and MF versions 10.2.0 and earlier are affected by the vulnerability. The affected software is used by over 2 million users in 130 countries, including the United States, the United Kingdom, and Canada.
What to do: Users should immediately stop using PaperCut NG and MF versions 10.2.0 and earlier. Security teams should review their current software versions and patch any affected systems. PaperCut has also released patches for the affected software, which can be downloaded from their website. IT departments should monitor their print queues for any suspicious activity and report any incidents to their security teams.