PT-2016-1938 · Adobe · Acrobat+1

Matthias Kaiser

·

Publicado

2016-05-05

·

Atualizado

2016-12-01

·

CVE-2016-1041

CVSS v3.1

10

Crítica

VetorAV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Adobe Reader versions (affected versions not specified) Adobe Acrobat versions (affected versions not specified)
Description The issue is related to insufficient access control in Adobe Reader and Adobe Acrobat, allowing a remote attacker to bypass restrictions on JavaScript API execution. This can be achieved through the ANAuthenticateResource Javascript API, which has restrictions that can be bypassed.
Recommendations For Adobe Reader, update to a version that addresses the access control issue, although the specific version is not provided. For Adobe Acrobat, consider disabling the ANAuthenticateResource Javascript API as a temporary workaround until a patch is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Improper Access Control

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

BDU:2016-01271
CVE-2016-1041
ZDI-16-288

Produtos afetados

Acrobat
Reader