First published: Wed Mar 09 2016(Updated: )
Untrusted search path vulnerability in Adobe Reader and Acrobat before 11.0.15, Acrobat and Acrobat Reader DC Classic before 15.006.30121, and Acrobat and Acrobat Reader DC Continuous before 15.010.20060 on Windows and OS X allows local users to gain privileges via a Trojan horse DLL in an unspecified directory.
Credit: psirt@adobe.com
Affected Software | Affected Version | How to fix |
---|---|---|
Adobe Acrobat Reader | <=11.0.14 | |
Adobe Acrobat | <=15.006.30119 | |
Adobe Acrobat | <=15.010.20059 | |
Adobe Acrobat Reader | <=11.0.14 | |
Adobe Acrobat Reader | <=15.010.20059 | |
Adobe Acrobat Reader | =15.006.30119 | |
Apple iOS and macOS | ||
Microsoft Windows |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-1008 is considered a moderate severity vulnerability that allows local users to gain privileges.
To resolve CVE-2016-1008, update Adobe Reader and Acrobat to versions 11.0.15, 15.006.30121, or later.
CVE-2016-1008 affects Adobe Reader and Acrobat versions prior to 11.0.15 and various versions of Acrobat DC.
CVE-2016-1008 is an untrusted search path vulnerability that can be exploited via a Trojan horse DLL.
Yes, you can verify your system's vulnerability to CVE-2016-1008 by checking if you are running an affected version of Adobe Reader or Acrobat.