CVE-2016-0936: Buffer Overflow
Adobe Reader and Acrobat before 11.0.14, Acrobat and Acrobat Reader DC Classic before 15.006.30119, and Acrobat and Acrobat Reader DC Continuous before 15.010.20056 on Windows and OS X allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via crafted JPEG 2000 data, a different vulnerability than CVE-2016-0931, CVE-2016-0933, CVE-2016-0938, CVE-2016-0939, CVE-2016-0942, CVE-2016-0944, CVE-2016-0945, and CVE-2016-0946.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2016-0936?
CVE-2016-0936 is classified as critical due to its potential for arbitrary code execution and denial of service.
How do I fix CVE-2016-0936?
To fix CVE-2016-0936, users should update Adobe Reader and Acrobat to version 11.0.14 or later for Acrobat Reader and 15.010.20056 or later for Acrobat DC.
What software versions are affected by CVE-2016-0936?
CVE-2016-0936 affects Adobe Reader and Acrobat versions before 11.0.14, and all versions of Acrobat and Acrobat Reader DC Classic before 15.006.30119.
Can CVE-2016-0936 be exploited to perform remote code execution?
Yes, CVE-2016-0936 can be exploited by attackers to execute arbitrary code on the affected systems.
Is there a workaround for CVE-2016-0936 if I cannot update immediately?
While the most effective mitigation is updating, users should avoid opening untrusted PDF files or email attachments until updates can be applied.