Junglewise Threat Intelligence

CVE-2026-6645: PaperCut Print Deploy insecure process execution in pc-printer-updater.exe

CVE-2026-6645 · Severity: info · CVSS 7.3 · Published 2026-06-22

Vendors: PaperCut.

Executive brief

PaperCut Print Deploy is a tool used by IT administrators to manage and distribute printer drivers to Windows computers. A security flaw in its update component allows a local user on a computer to trick the software into running a malicious file instead of a legitimate system utility. Because this software runs with high-level administrative privileges, an attacker could use this flaw to gain full control over the affected Windows machine.

Technical details

An uncontrolled search path vulnerability (CWE-427) exists in the pc-printer-updater.exe component of PaperCut Print Deploy Client for Windows. The application attempts to execute a secondary system utility using an unqualified file reference rather than an absolute path. This behavior allows a local attacker with write access to a directory in the system's search path to plant a malicious executable with the same name as the expected utility. When the updater runs with SYSTEM privileges, it may execute the attacker's binary, leading to full host compromise. This issue is resolved in version 1.10.4178.

Affected products

  • PaperCut Print Deploy < 1.10.4178

Timeline

  • 2026-06-22: disclosed
  • 2026-06-22: advisory

References