PT-2015-2333 · Adobe · Reader+5

Abdulaziz Hariri

+1

·

Published

2015-10-13

·

Updated

2021-09-08

·

CVE-2015-5583

CVSS v2.0

4.3

Medium

VectorAV:N/AC:M/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions Adobe Acrobat versions (affected versions not specified) Adobe Reader versions (affected versions not specified) Adobe Flash Player versions (affected versions not specified) Adobe Integrated Runtime versions (affected versions not specified) Adobe Acrobat Document Cloud versions (affected versions not specified) Adobe Reader Document Cloud versions (affected versions not specified)
Description The issue is related to insufficient access control mechanisms in the software, allowing a remote attacker to bypass the sandbox and access protected information by creating a print job on a remote printer. This can lead to sensitive information disclosure.
Recommendations For Adobe Acrobat, update to a version that addresses the access control mechanism weaknesses. For Adobe Reader, consider disabling the print functionality to remote printers until a patch is available. For Adobe Flash Player and Adobe Integrated Runtime, restrict access to sensitive information and avoid using remote printing services until the issue is resolved. For Adobe Acrobat Document Cloud and Adobe Reader Document Cloud, avoid using the print functionality on remote printers and consider disabling access to sensitive documents until a fix is provided. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2015-11698
CVE-2015-5583
ZDI-15-468

Affected Products

Acrobat
Acrobat Document Cloud
Flash Player
Integrated Runtime
Reader
Reader Document Cloud