ZDI-26-732: Foxit PDF Reader importIcon NTLM Response Information Disclosure Vulnerability
ZDI disclosed an NTLM response leak in Foxit PDF Reader importIcon, tracked as CVE-2026-91796.
The Zero Day Initiative published ZDI-26-732, an information-disclosure flaw in Foxit PDF Reader's importIcon handling. A remote attacker can obtain NTLM responses if a user opens a malicious file or visits a malicious page. ZDI assigned CVSS 3.3 and CVE-2026-91796. The advisory does not report active exploitation.
- importIcon handling can leak NTLM authentication responses.
- Attacker must lure the user to a page or file.
- ZDI rates the issue CVSS 3.3.
- Tracked as CVE-2026-91796; no exploitation reported.
Vulnerabilities mentionedAll →
- CVE-2026-917966.1—Secure Reading Mode Bypass in Foxit PDF Editor/Reader Leaks NTLM Hashes via SMBpublished · Foxit PDF Editor
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-91796 | Secure Reading Mode Bypass in Foxit PDF Editor/Reader Leaks NTLM Hashes via SMB Foxit PDF Editor and Reader fail to enforce permission verification for Secure Reading Mode, a protection mechanism failure (CWE-693) that lets a malicious PDF silently trigger an outbound SMB authentication request without any security prompt. When a victim simply opens the crafted PDF, their Windows machine sends NTLM authentication responses (per the related ZDI advisory, via a construct such as the importIcon action) to an attacker-controlled SMB server, exposing the user's credential hash, which can be cracked offline or relayed for lateral movement. The flaw requires user interaction but no privileges, and affects both the free Reader and paid Editor products; per the CVSS vector, availability is also impacted (A:H). No public proof of concept is known and there is no evidence of in-the-wild exploitation, though the attack is trivially deliverable via emailed or downloaded PDFs. |
This vulnerability allows remote attackers to disclose NTLM responses on affected installations of Foxit PDF Reader. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 3.3. The following CVEs are assigned: CVE-2026-91796.
This source does not provide full text. Read it at zerodayinitiative.com.