First published: Thu Jun 04 2020(Updated: )
An issue was discovered in Foxit PhantomPDF before 8.3.6. It allows arbitrary application execution via an embedded executable file in a PDF portfolio, aka FG-VD-18-029.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Foxit PhantomPDF | <8.3.6 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-21244 has a high severity rating due to its ability to allow arbitrary application execution.
To fix CVE-2018-21244, users should update Foxit PhantomPDF to version 8.3.6 or later.
CVE-2018-21244 can lead to potential system compromise by allowing malicious executables to run.
CVE-2018-21244 affects all versions of Foxit PhantomPDF before 8.3.6.
CVE-2018-21244 is considered a remote vulnerability, as it can be exploited through malicious PDF files.