← back
CVE-2023-39143criticalobserved exploitationCWE-22

CVE-2023-39143

100Vexday Risk Score

Patch now. It exploitation observed by VulnCheck and has a working public exploit.

ssvc Actcvss 9.8epss 80%
from disclosure to weapon797 days
Published on NVDAug 4
1st PoC+797d
VulnCheck+805d
exploitation probability
80%top 1% of all CVEs
observed exploitation
yesVulnCheck
1 public exploit(s)
PaperCut NG and PaperCut MF before 22.1.3 on Windows allow path traversal, enabling attackers to upload, read, or delete arbitrary files. This leads to remote code execution when external device integration is enabled (a very common configuration).
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Affected products
n/a · n/a
⚠ Public resources, to assess the exposure of systems you control or are authorized to test. Test only with authorization.