CVE-2024-4712

An arbitrary file creation vulnerability exists in PaperCut NG/MF that only affects Windows servers with Web Print enabled.This specific flaw exists within the image-handler process, which can incorrectly create files that dont exist when a maliciously formed payload is provided. This can lead to local privilege escalation.

Note: 

This CVE has been split into two (CVE-2024-4712 and CVE-2024-8405) and its been rescored with a "Privileges Required (PR)" rating of low, and Attack Complexity (AC) rating of low, reflecting the worst-case scenario where an Administrator has granted local login access to standard network users on the host server.
Command Injection
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
7.8 HIGH
LOCAL
LOW
LOW
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
PaperCutCNA
7.8 HIGH
LOCAL
LOW
LOW
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
CISA-ADPADP
---
---
CVEADP
---
---