First published: Wed May 11 2016(Updated: )
Untrusted search path vulnerability in Adobe Reader and Acrobat before 11.0.16, Acrobat and Acrobat Reader DC Classic before 15.006.30172, and Acrobat and Acrobat Reader DC Continuous before 15.016.20039 on Windows and OS X allows local users to gain privileges via a Trojan horse resource in an unspecified directory, a different vulnerability than CVE-2016-1087 and CVE-2016-4106.
Credit: psirt@adobe.com
Affected Software | Affected Version | How to fix |
---|---|---|
Apple iOS and macOS | ||
Microsoft Windows | ||
Adobe Acrobat Reader | <=11.0.15 | |
Adobe Acrobat | <=15.006.30121 | |
Adobe Acrobat | <=15.010.20060 | |
Adobe Acrobat Reader | <=15.006.30121 | |
Adobe Acrobat Reader | <=15.010.20060 | |
Adobe Acrobat Reader | <=11.0.15 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-1090 is rated as a low-severity vulnerability.
To fix CVE-2016-1090, update Adobe Reader and Acrobat to version 11.0.16 or later, or upgrade to a newer version of Acrobat DC.
CVE-2016-1090 affects users of Adobe Reader and Acrobat versions prior to 11.0.16 and specific versions of Acrobat DC.
CVE-2016-1090 requires local access, meaning it cannot be exploited remotely.
The main threat of CVE-2016-1090 is that local users could gain elevated privileges through a Trojan horse resource.