First published: Wed Oct 14 2015(Updated: )
Adobe Reader and Acrobat 10.x before 10.1.16 and 11.x before 11.0.13, Acrobat and Acrobat Reader DC Classic before 2015.006.30094, and Acrobat and Acrobat Reader DC Continuous before 2015.009.20069 on Windows mishandle junctions in the Synchronizer directory, which allows attackers to delete arbitrary files via Adobe Collaboration Sync, a related issue to CVE-2015-2428.
Credit: psirt@adobe.com
Affected Software | Affected Version | How to fix |
---|---|---|
Adobe Acrobat Reader | >=10.0<=10.1.15 | |
Adobe Acrobat Reader | >=11.0.0<=11.0.12 | |
Adobe Acrobat Reader | >=15.006.30060<15.006.30094 | |
Adobe Acrobat Reader | >=15.008.20082<15.009.20069 | |
Adobe Acrobat Reader Notification Manager | >=10.0<=10.1.15 | |
Adobe Acrobat Reader Notification Manager | >=11.0.0<=11.0.12 | |
Adobe Acrobat Reader Notification Manager | >=15.006.30060<15.006.30094 | |
Adobe Acrobat Reader Notification Manager | >=15.008.20082<15.009.20069 | |
Apple iOS and macOS | ||
Microsoft Windows |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2015-7829 is rated as a critical severity vulnerability due to its potential to allow attackers to delete arbitrary files.
To mitigate CVE-2015-7829, users should update Adobe Reader and Acrobat to the latest versions available for their software.
CVE-2015-7829 affects Adobe Reader and Acrobat versions prior to 10.1.16, 11.0.13, and various versions of Acrobat Reader DC.
CVE-2015-7829 primarily impacts the Windows platform for affected Adobe products.
CVE-2015-7829 is a file manipulation vulnerability that allows unauthorized file deletion through mishandled junctions.