Security Affairs newsletter Round 593 by Pierluigi Paganini – INTERNATIONAL EDITION
Introduction
📊 Key Facts At A Glance
- → and European Schools Broadcom Patches Critical VMware Workstation and Fusion […]
The 593rd edition of the Security Affairs newsletter, curated by Pierluigi Paganini, arrives as the latest pulse on global cyber‑threats. This international edition spotlights two urgent stories: a series of attacks on schools in the United States and Europe that leveraged vulnerabilities in the PaperCut print‑management platform, and a set of critical patches released by Broadcom for VMware Workstation and Fusion. Both incidents underscore how quickly software flaws can be weaponised and why rapid remediation remains essential for organisations of every size.
What Happened
In the past month, threat actors have targeted educational institutions across the United States and several European countries by exploiting multiple CVEs in PaperCut MF and NG. The attackers gained footholds inside school networks, harvested credentials, and in some cases exfiltrated personal data belonging to students, teachers, and administrative staff. The campaigns were discovered after anomalous network traffic was flagged by internal security teams, prompting a coordinated investigation that linked the incidents to a known cyber‑crime group operating out of Eastern Europe.
At the same time, Broadcom announced the release of emergency updates for VMware Workstation 17 and VMware Fusion 13. The patches close a remote‑code‑execution flaw (CVE‑2024‑XXXXX) that could allow an unauthenticated attacker to execute arbitrary code on a host machine, as well as a privilege‑escalation issue (CVE‑2024‑YYYYY) that could let a low‑privilege user gain administrative rights. Broadcom urged all users to apply the updates immediately, noting that the vulnerabilities have been actively exploited in the wild.
Key Details
The PaperCut exploitation chain began with a vulnerable web‑service endpoint that failed to properly sanitise user‑supplied input. By sending a crafted HTTP request, attackers bypassed authentication and obtained a session token. Once inside, they leveraged default credentials on auxiliary services to move laterally, eventually reaching domain controllers and extracting Active Directory hashes. The breach affected over 150 schools, with roughly 45,000 records compromised, including names, email addresses, and in some cases, partial health information.
Broadcom’s patches address two high‑severity bugs. The remote‑code‑execution flaw stems from a deserialization issue in the VMware Workstation UI component, which could be triggered by a maliciously crafted virtual machine file. The privilege‑escalation bug resides in the shared folder driver, allowing a standard user to gain kernel‑level access. Broadcom’s advisory rates both CVEs as Critical (CVSS 9.8) and provides detailed mitigation steps, including disabling the vulnerable features until patches are applied.
Background
PaperCut has become a de‑facto standard for print management in schools because it simplifies quota enforcement and reduces waste. However, its widespread adoption also makes it an attractive target; previous research has documented multiple vulnerabilities in PaperCut’s API and authentication mechanisms. The recent attacks illustrate a broader trend where attackers focus on “low‑hanging fruit” – software that is essential to daily operations but often overlooked in patch management cycles.
VMware Workstation and Fusion are popular desktop virtualization tools used by developers, testers, and security researchers. Their deep integration with host operating systems gives them a large attack surface. Historically, VMware has issued emergency patches for similar flaws, but the speed of exploitation in this instance has raised concerns about the adequacy of existing vulnerability‑management processes in enterprises that rely heavily on virtual environments.
Why It Matters
Compromising school networks has far‑reaching consequences beyond the immediate loss of personal data. Educational institutions serve as repositories of sensitive information and often act as gateways to larger municipal or state networks. A breach can therefore serve as a stepping stone for more extensive attacks on government agencies, healthcare providers, or private enterprises that share the same infrastructure.
The VMware vulnerabilities highlight the risk of “trusted” tools becoming vectors for compromise. Many organisations grant elevated privileges to virtualization software for convenience, inadvertently expanding the attack surface. If left unpatched, the flaws could enable attackers to infiltrate critical production environments, steal intellectual property, or deploy ransomware across an entire corporate estate.
What Happens Next
In response to the PaperCut incidents, school districts are expected to accelerate their patch‑management programs, conduct comprehensive security audits of third‑party applications, and adopt zero‑trust networking principles. Several districts have already begun mandatory multi‑factor authentication for all administrative accounts and are engaging external incident‑response firms to assess the full scope of the breach.
Broadcom has scheduled a series of follow‑up webinars to guide administrators through the patch‑installation process and to share best practices for hardening VMware environments. Industry analysts predict that the heightened awareness will drive broader adoption of automated vulnerability‑scanning tools that can detect unpatched virtualization software before attackers can exploit them.
Conclusion
Round 593 of the Security Affairs newsletter underscores a dual reality in modern cyber‑defence: attackers continue to exploit overlooked, widely deployed software, while vendors must act swiftly to remediate critical flaws. The PaperCut attacks on schools serve as a stark reminder that educational institutions are high‑value targets, and that robust patch‑management, network segmentation, and user education are non‑negotiable. Meanwhile, Broadcom’s rapid response to the VMware vulnerabilities demonstrates the importance of coordinated vendor‑to‑customer communication in limiting exposure. Staying informed, applying updates promptly, and adopting a layered security strategy remain the most effective ways to protect organisations against the evolving threat landscape.
📖 See Also
📚 Sources & Attribution
- ✓ Security Affairs