CVE-2015-3072: Critical severity adobe acrobat reader vulnerability
Adobe Reader and Acrobat 10.x before 10.1.14 and 11.x before 11.0.11 on Windows and OS X allow attackers to bypass intended restrictions on JavaScript API execution via unspecified vectors, a different vulnerability than CVE-2015-3060, CVE-2015-3061, CVE-2015-3062, CVE-2015-3063, CVE-2015-3064, CVE-2015-3065, CVE-2015-3066, CVE-2015-3067, CVE-2015-3068, CVE-2015-3069, CVE-2015-3071, CVE-2015-3073, and CVE-2015-3074.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2015-3072?
CVE-2015-3072 is classified as a critical vulnerability that allows attackers to bypass JavaScript API execution restrictions.
How do I fix CVE-2015-3072?
To fix CVE-2015-3072, users should upgrade Adobe Reader and Acrobat to the latest versions available: 10.1.14 or later for 10.x, and 11.0.11 or later for 11.x.
What versions of Adobe Acrobat are affected by CVE-2015-3072?
CVE-2015-3072 affects Adobe Reader and Acrobat 10.x versions prior to 10.1.14 and 11.x versions prior to 11.0.11 on both Windows and macOS.
Can CVE-2015-3072 be exploited remotely?
Yes, CVE-2015-3072 can potentially be exploited remotely through specially crafted PDFs that leverage the vulnerability.
What are the potential impacts of exploiting CVE-2015-3072?
Exploiting CVE-2015-3072 may allow an attacker to execute arbitrary JavaScript code in the context of the user running the affected software.