CVE-2016-1040: Critical severity apple ios and macos vulnerability
Adobe Reader and Acrobat before 11.0.16, Acrobat and Acrobat Reader DC Classic before 15.006.30172, and Acrobat and Acrobat Reader DC Continuous before 15.016.20039 on Windows and OS X allow attackers to bypass JavaScript API execution restrictions via unspecified vectors, a different vulnerability than CVE-2016-1038, CVE-2016-1039, CVE-2016-1041, CVE-2016-1042, CVE-2016-1044, CVE-2016-1062, and CVE-2016-1117.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2016-1040?
CVE-2016-1040 is classified as a moderate severity vulnerability that allows attackers to bypass JavaScript API execution restrictions.
How do I fix CVE-2016-1040?
To address CVE-2016-1040, you should update Adobe Reader and Acrobat to the latest version as specified in Adobe's security advisory.
What versions are affected by CVE-2016-1040?
CVE-2016-1040 affects Adobe Reader and Acrobat versions before 11.0.16, Acrobat DC Classic before 15.006.30172, and Acrobat DC Continuous before 15.016.20039.
What are the potential risks of CVE-2016-1040?
The potential risks of CVE-2016-1040 include unauthorized execution of JavaScript code, which could lead to data theft or system compromise.
Are all operating systems affected by CVE-2016-1040?
No, CVE-2016-1040 primarily affects Adobe products on Windows and OS X, but macOS Yosemite is noted as not vulnerable.