First published: Thu Jan 14 2016(Updated: )
Adobe Reader and Acrobat before 11.0.14, Acrobat and Acrobat Reader DC Classic before 15.006.30119, and Acrobat and Acrobat Reader DC Continuous before 15.010.20056 on Windows and OS X mishandle the Global object, which allows attackers to bypass JavaScript API execution restrictions via unspecified vectors.
Credit: psirt@adobe.com
Affected Software | Affected Version | How to fix |
---|---|---|
Adobe Acrobat Reader DC | <=15.006.30097 | |
Adobe Acrobat Reader DC | <=15.009.20077 | |
Adobe Acrobat Reader | <=15.006.30097 | |
Adobe Acrobat Reader | <=15.009.20077 | |
Apple iOS and macOS | ||
Microsoft Windows Operating System | ||
Adobe Acrobat Reader Notification Manager | <=11.0.13 | |
Adobe Acrobat Reader Notification Manager | =11.0.0 | |
Adobe Acrobat Reader Notification Manager | =11.0.1 | |
Adobe Acrobat Reader Notification Manager | =11.0.2 | |
Adobe Acrobat Reader Notification Manager | =11.0.3 | |
Adobe Acrobat Reader Notification Manager | =11.0.4 | |
Adobe Acrobat Reader Notification Manager | =11.0.5 | |
Adobe Acrobat Reader Notification Manager | =11.0.6 | |
Adobe Acrobat Reader Notification Manager | =11.0.7 | |
Adobe Acrobat Reader Notification Manager | =11.0.8 | |
Adobe Acrobat Reader Notification Manager | =11.0.9 | |
Adobe Acrobat Reader Notification Manager | =11.0.10 | |
Adobe Acrobat Reader Notification Manager | =11.0.11 | |
Adobe Acrobat Reader Notification Manager | =11.0.12 | |
Adobe Acrobat Reader | <=11.0.13 | |
Adobe Acrobat Reader | =11.0.0 | |
Adobe Acrobat Reader | =11.0.1 | |
Adobe Acrobat Reader | =11.0.2 | |
Adobe Acrobat Reader | =11.0.3 | |
Adobe Acrobat Reader | =11.0.4 | |
Adobe Acrobat Reader | =11.0.5 | |
Adobe Acrobat Reader | =11.0.6 | |
Adobe Acrobat Reader | =11.0.7 | |
Adobe Acrobat Reader | =11.0.8 | |
Adobe Acrobat Reader | =11.0.9 | |
Adobe Acrobat Reader | =11.0.10 | |
Adobe Acrobat Reader | =11.0.11 | |
Adobe Acrobat Reader | =11.0.12 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-0943 has a critical severity rating due to its potential to allow attackers to bypass JavaScript API execution restrictions.
To fix CVE-2016-0943, users should upgrade to the latest versions of Adobe Reader and Acrobat specified in the security advisory.
CVE-2016-0943 affects Adobe Reader and Acrobat versions prior to 11.0.14 and some versions of Acrobat DC prior to 15.010.20056.
CVE-2016-0943 can be exploited by attackers to bypass security restrictions and execute unauthorized JavaScript code.
CVE-2016-0943 is applicable to both Windows and macOS versions of Adobe Reader and Acrobat.