PT-2019-15171 · Pdf Xchange · Pdf-Xchange Editor

CVE-2019-17497

·

Publicado

2019-10-10

·

Atualizado

2024-11-27

CVSS v3.1

6.5

Média

VetorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions PDF-XChange Editor versions prior to 8.0.330.0
Description The issue allows for NTLM SSO hash theft using crafted FDF or XFDF files. This can occur when a link to a file, such as '192.168.0.2C$file.pdf', is accessed without user interaction, resulting in the transmission of an NTLM hash.
Recommendations For versions prior to 8.0.330.0, update to version 8.0.330.0 or later to resolve the issue. As a temporary workaround, consider restricting access to crafted FDF or XFDF files until the update is applied. Avoid using links to files that may trigger the transmission of NTLM hashes without user interaction.

Exploit

Correção

Insufficiently Protected Credentials

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2019-17497

Produtos afetados

Pdf-Xchange Editor