6.5
CVSSv3

CVE-2019-17497

Published: 11/10/2019 Updated: 16/10/2019
CVSS v2 Base Score: 4.3 | Impact Score: 2.9 | Exploitability Score: 8.6
CVSS v3 Base Score: 6.5 | Impact Score: 3.6 | Exploitability Score: 2.8
VMScore: 383
Vector: AV:N/AC:M/Au:N/C:P/I:N/A:N

Vulnerability Summary

Tracker PDF-XChange Editor prior to 8.0.330.0 has an NTLM SSO hash theft vulnerability using crafted FDF or XFDF files (a related issue to CVE-2018-4993). For example, an NTLM hash is sent for a link to \\192.168.0.2\C$\file.pdf without user interaction.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

tracker-software pdf-xchange editor

Github Repositories

POC Files for CVE-2019-17497

CVE-2019-17497 CVE Details PDF-XChange Editor before 803300 has an NTLM SSO hash theft vulnerability using crafted FDF or XFDF files (a related issue to CVE-2018-4993) For example, an NTLM hash is sent for a link to \attackerloca\C$\eeepdf without user interaction Original Writeup Since the original writeup didn't include the POC as files, I recreated them myself