CVE-2015-6716: Medium severity adobe acrobat reader vulnerability
The ANSendForFormDistribution method in Adobe Reader and Acrobat 10.x before 10.1.16 and 11.x before 11.0.13, Acrobat and Acrobat Reader DC Classic before 2015.006.30094, and Acrobat and Acrobat Reader DC Continuous before 2015.009.20069 on Windows and OS X allows attackers to bypass JavaScript API execution restrictions via unspecified vectors, a different vulnerability than CVE-2015-6707, CVE-2015-6708, CVE-2015-6709, CVE-2015-6710, CVE-2015-6711, CVE-2015-6712, CVE-2015-6713, CVE-2015-6714, CVE-2015-6715, CVE-2015-6717, CVE-2015-6718, CVE-2015-6719, CVE-2015-6720, CVE-2015-6721, CVE-2015-6722, CVE-2015-6723, CVE-2015-6724, CVE-2015-6725, CVE-2015-7614, CVE-2015-7616, CVE-2015-7618, CVE-2015-7619, CVE-2015-7620, and CVE-2015-7623.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2015-6716?
CVE-2015-6716 is classified as a critical vulnerability allowing attacks that bypass JavaScript API restrictions.
What products are affected by CVE-2015-6716?
CVE-2015-6716 affects Adobe Reader and Acrobat versions 10.x prior to 10.1.16, 11.x prior to 11.0.13, and certain versions of Acrobat DC.
How do I fix CVE-2015-6716?
To fix CVE-2015-6716, update Adobe Reader and Acrobat to the latest versions available from Adobe.
What types of attacks can exploit CVE-2015-6716?
Attackers can exploit CVE-2015-6716 to execute JavaScript commands that could compromise system security.
Is CVE-2015-6716 a cross-platform vulnerability?
Yes, CVE-2015-6716 is present on both Windows and macOS versions of the affected Adobe software.