First published: Thu Jun 04 2020(Updated: )
An issue was discovered in Foxit PhantomPDF before 8.3.7. It allows NTLM credential theft via a GoToE or GoToR action.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Foxit PhantomPDF | <8.3.7 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-21237 has a moderate severity rating due to the potential for NTLM credential theft.
To fix CVE-2018-21237, update Foxit PhantomPDF to version 8.3.7 or later.
CVE-2018-21237 affects users of Foxit PhantomPDF versions prior to 8.3.7.
CVE-2018-21237 can be exploited through specially crafted GoToE and GoToR actions in PDF files.
If you cannot update, implement network security measures to mitigate the risk of NTLM credential theft.