CVE-2015-7614: Medium severity adobe acrobat reader vulnerability
Adobe Reader and Acrobat 10.x before 10.1.16 and 11.x before 11.0.13, Acrobat and Acrobat Reader DC Classic before 2015.006.30094, and Acrobat and Acrobat Reader DC Continuous before 2015.009.20069 on Windows and OS X allow attackers to bypass JavaScript API execution restrictions and execute arbitrary commands via an app.launchURL call, a different vulnerability than CVE-2015-6707, CVE-2015-6708, CVE-2015-6709, CVE-2015-6710, CVE-2015-6711, CVE-2015-6712, CVE-2015-6713, CVE-2015-6714, CVE-2015-6715, CVE-2015-6716, CVE-2015-6717, CVE-2015-6718, CVE-2015-6719, CVE-2015-6720, CVE-2015-6721, CVE-2015-6722, CVE-2015-6723, CVE-2015-6724, CVE-2015-6725, CVE-2015-7616, CVE-2015-7618, CVE-2015-7619, CVE-2015-7620, and CVE-2015-7623.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2015-7614?
CVE-2015-7614 is classified as a critical vulnerability allowing unauthorized execution of JavaScript in Adobe products.
How do I fix CVE-2015-7614?
To fix CVE-2015-7614, update your Adobe Reader and Acrobat software to the latest versions available.
Which Adobe products are affected by CVE-2015-7614?
CVE-2015-7614 affects Adobe Reader and Acrobat 10.x and 11.x, as well as Adobe Acrobat and Reader DC before specific versions.
What type of attack does CVE-2015-7614 enable?
CVE-2015-7614 allows attackers to bypass JavaScript API execution restrictions and execute malicious scripts.
Is my operating system vulnerable to CVE-2015-7614?
CVE-2015-7614 impacts Adobe software running on Windows and macOS versions specified, but the OS itself is not directly vulnerable.