CVE-2018-21244: Malicious File Upload
Published Jun 4, 2020
·Updated
An issue was discovered in Foxit PhantomPDF before 8.3.6. It allows arbitrary application execution via an embedded executable file in a PDF portfolio, aka FG-VD-18-029.
Affected Software
1 affected component
Foxitsoftware Phantompdf<8.3.6
Event History
Jun 4, 2020
CVE Published
via MITRE·04:17 PM
Data Sourced
via MITRE·04:17 PM
Description
Frequently Asked Questions
1
What is the severity of CVE-2018-21244?
CVE-2018-21244 has a high severity rating due to its ability to allow arbitrary application execution.
2
How do I fix CVE-2018-21244?
To fix CVE-2018-21244, users should update Foxit PhantomPDF to version 8.3.6 or later.
3
What impact does CVE-2018-21244 have on my system?
CVE-2018-21244 can lead to potential system compromise by allowing malicious executables to run.
4
Which versions of Foxit PhantomPDF are affected by CVE-2018-21244?
CVE-2018-21244 affects all versions of Foxit PhantomPDF before 8.3.6.
5
Is CVE-2018-21244 a local or remote vulnerability?
CVE-2018-21244 is considered a remote vulnerability, as it can be exploited through malicious PDF files.