First published: Wed May 11 2016(Updated: )
Untrusted search path vulnerability in Adobe Reader and Acrobat before 11.0.16, Acrobat and Acrobat Reader DC Classic before 15.006.30172, and Acrobat and Acrobat Reader DC Continuous before 15.016.20039 on Windows and OS X allows local users to gain privileges via a Trojan horse resource in an unspecified directory, a different vulnerability than CVE-2016-1087 and CVE-2016-1090.
Credit: psirt@adobe.com
Affected Software | Affected Version | How to fix |
---|---|---|
Apple iOS and macOS | ||
Microsoft Windows | ||
Adobe Acrobat Reader | <=11.0.15 | |
Adobe Acrobat | <=15.006.30121 | |
Adobe Acrobat | <=15.010.20060 | |
Adobe Acrobat Reader | <=15.006.30121 | |
Adobe Acrobat Reader | <=15.010.20060 | |
Adobe Acrobat Reader | <=11.0.15 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2016-4106 is considered to have a critical severity level as it allows local users to gain elevated privileges.
To fix CVE-2016-4106, users should update Adobe Reader and Acrobat to the latest versions available.
CVE-2016-4106 affects Adobe Reader and Acrobat versions prior to 11.0.16 and earlier versions of Acrobat DC before 15.016.20039.
No, CVE-2016-4106 requires local access to the vulnerable system for exploitation.
The potential impacts of CVE-2016-4106 include unauthorized privilege escalation and execution of arbitrary code by local users.