First published: Wed Jul 13 2016(Updated: )
Adobe Reader and Acrobat before 11.0.17, Acrobat and Acrobat Reader DC Classic before 15.006.30198, and Acrobat and Acrobat Reader DC Continuous before 15.017.20050 on Windows and OS X allow attackers to bypass JavaScript API execution restrictions via unspecified vectors.
Credit: psirt@adobe.com
Affected Software | Affected Version | How to fix |
---|---|---|
Apple iOS and macOS | ||
Microsoft Windows Operating System | ||
Adobe Acrobat Reader | <=11.0.16 | |
Adobe Acrobat Reader DC | <=15.006.30174 | |
Adobe Acrobat Reader DC | <=15.016.20045 | |
Adobe Acrobat Reader | <=15.006.30174 | |
Adobe Acrobat Reader | <=15.016.20045 | |
Adobe Acrobat Reader | <=11.0.16 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2016-4215 is classified as moderate due to the potential for JavaScript API execution bypass.
To fix CVE-2016-4215, update Adobe Reader and Acrobat to versions 11.0.17 or newer, or update to Acrobat and Acrobat Reader DC Classic version 15.006.30198 and above.
CVE-2016-4215 affects Adobe Reader and Acrobat versions prior to 11.0.17 and DC versions before 15.006.30198.
CVE-2016-4215 can potentially allow attackers to execute restricted JavaScript code, which may lead to exploitation.
CVE-2016-4215 impacts users on Windows and OS X platforms using vulnerable versions of Adobe Reader and Acrobat.