Back

HIGH

Arbitrary File Deletion in PaperCut NG/MF Web Print Hot folder

Published Sep 26, 2024

Description

An arbitrary file deletion vulnerability exists in PaperCut NG/MF, specifically affecting Windows servers with Web Print enabled. To exploit this vulnerability, an attacker must first obtain local login access to the Windows Server hosting PaperCut NG/MF and be capable of executing low-privilege code directly on the server via the web-print-hot-folder.

Important: In most installations, this risk is mitigated by the default Windows Server configuration, which restricts local login access to Administrators only. However, this vulnerability could pose a risk to customers who allow non-administrative users to log into the local console of the Windows environment hosting the PaperCut NG/MF application server.

Update:

This CVE has been updated in May 2025 to update the fixed version and fix process. Please refer to the May 2025 Security Bulletin.

Note:

This CVE has been split from CVE-2024-3037.

Affected products

Remediation

No remediation recorded yet.

Weaknesses (1)

References (3)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner PaperCut
Published Sep 26, 2024
Updated May 13, 2025
Reserved Sep 4, 2024
CISA Vulnrichment
Updated Sep 26, 2024
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity n/a
Public date n/a
ENISA EUVD
Assigner PaperCut
Published Sep 26, 2024
Updated May 13, 2025
Exploited since n/a
EUVD-2024-49151