CVE-2018-21239: Medium severity foxit phantompdf vulnerability
Published Jun 4, 2020
·Updated
An issue was discovered in Foxit Reader and PhantomPDF before 9.2. It allows NTLM credential theft via a GoToE or GoToR action.
Affected Software
2 affected components
Foxitsoftware Phantompdf<9.2
Foxitsoftware Reader<9.2
Event History
Jun 4, 2020
CVE Published
via MITRE·04:31 PM
Data Sourced
via MITRE·04:31 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2018-21239?
The severity of CVE-2018-21239 is medium with a CVSS score of 5.3.
2
Which software versions are affected by CVE-2018-21239?
Foxit Reader and PhantomPDF versions up to exclusive 9.2 are affected by CVE-2018-21239.
3
How can NTLM credential theft occur via CVE-2018-21239?
NTLM credential theft can occur via a GoToE or GoToR action in Foxit Reader and PhantomPDF versions before 9.2.
4
How can I fix CVE-2018-21239?
To fix CVE-2018-21239, users should update Foxit Reader and PhantomPDF to version 9.2 or later.
5
Where can I find more information about CVE-2018-21239?
More information about CVE-2018-21239 can be found on the Foxit Software security bulletins page.