CVE-2023-27350 is an unauthenticated remote code execution flaw in PaperCut MF and NG print management software, permitting code execution as SYSTEM. PaperCut released a patch in March 2023. Reporting places exploitation from around 13 April 2023, and CISA subsequently issued a joint advisory.
Both the Cl0p and LockBit operations were reported using it, along with other actors; a group identifying itself as Bl00dy was reported targeting education sector servers in early May.
Nobody Inventories The Print Server
Print management is administrative plumbing. It is installed to meter and charge for printing, it runs on a server nobody visits, and it typically runs with high privilege because managing printers requires it.
That combination — high privilege, low attention, frequently reachable — is the profile we keep recording. At 22-0930 it was on-premises Exchange; at 22-0118 a self-service password tool; at 23-1010 a network appliance. The vulnerable thing is rarely the system anyone would name if asked what mattered.
Competitors Do Not Compete On Vulnerabilities
Cl0p and LockBit were rivals for affiliates, victims and reputation. Both adopted the same flaw within weeks of exploitation beginning.
An exploitable vulnerability is not a competitive asset once it is public; it is shared infrastructure, and the window between disclosure and mass exploitation is the only variable a defender controls. We have recorded the same convergence at 23-0203 and 23-0601, where a single file transfer flaw supplied a whole season of victims.
The Patch Preceded The Exploitation
A fix existed roughly a month before attacks began. This is not a zero-day story; it is a patch-application story, and the population reached was the population that had not updated an unglamorous internal server.
We filed that pattern at 22-0118, where a humanitarian organisation was reached through a flaw fixed months earlier, and at 23-0518. The desk does not read it as negligence: the organisations that fall to this are the ones without an inventory complete enough to know the server exists.
Compiled from vendor research, CISA’s joint advisory and contemporaneous reporting, listed below. Actor naming here follows the vendors’ own clustering and is carried as attribution, not as established fact. No victim count is asserted — no authoritative total was published. No exploit detail or indicator is reproduced. Graded high. Corrections: corrections@forensicpost.com.