First published: Wed May 11 2016(Updated: )
Adobe Reader and Acrobat before 11.0.16, Acrobat and Acrobat Reader DC Classic before 15.006.30172, and Acrobat and Acrobat Reader DC Continuous before 15.016.20039 on Windows and OS X allow attackers to obtain sensitive information from process memory via unspecified vectors, a different vulnerability than CVE-2016-1092.
Credit: psirt@adobe.com
Affected Software | Affected Version | How to fix |
---|---|---|
Apple iOS and macOS | ||
Microsoft Windows | ||
Adobe Acrobat Reader | <=11.0.15 | |
Adobe Acrobat | <=15.006.30121 | |
Adobe Acrobat | <=15.010.20060 | |
Adobe Acrobat Reader | <=15.006.30121 | |
Adobe Acrobat Reader | <=15.010.20060 | |
Adobe Acrobat Reader | <=11.0.15 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-1079 has a moderate severity level as it allows attackers to obtain sensitive information from process memory.
To fix CVE-2016-1079, update Adobe Reader and Acrobat to their latest versions: 11.0.16 or later for Adobe Reader and 15.006.30172 or later for Acrobat DC.
CVE-2016-1079 affects Adobe Reader and Acrobat versions before 11.0.16 and Acrobat DC Classic versions before 15.006.30172.
CVE-2016-1079 does not specify remote exploitation capabilities, so it is generally considered to require local access.
No, macOS itself is not listed as vulnerable to CVE-2016-1079, but certain versions of Adobe applications on macOS are affected.