Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2016-1008


Untrusted search path vulnerability in Adobe Reader and Acrobat before 11.0.15, Acrobat and Acrobat Reader DC Classic before 15.006.30121, and Acrobat and Acrobat Reader DC Continuous before 15.010.20060 on Windows and OS X allows local users to gain privileges via a Trojan horse DLL in an unspecified directory.


Published

2016-03-09T11:59:38.390

Last Modified

2025-04-12T10:46:40.837

Status

Deferred

Source

[email protected]

Severity

CVSSv3.0: 8.4 (HIGH)

CVSSv2 Vector

AV:L/AC:L/Au:N/C:C/I:C/A:C

  • Access Vector: LOCAL
  • Access Complexity: LOW
  • Authentication: NONE
  • Confidentiality Impact: COMPLETE
  • Integrity Impact: COMPLETE
  • Availability Impact: COMPLETE
Exploitability Score

3.9

Impact Score

10.0

Weaknesses
  • Type: Primary
    CWE-20

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application adobe acrobat ≤ 11.0.14 Yes
Application adobe acrobat_dc ≤ 15.006.30119 Yes
Application adobe acrobat_dc ≤ 15.010.20059 Yes
Application adobe acrobat_reader ≤ 11.0.14 Yes
Application adobe acrobat_reader_dc ≤ 15.010.20059 Yes
Application adobe acrobat_reader_dc 15.006.30119 Yes
Operating System apple mac_os_x * No
Operating System microsoft windows * No

References