PT-2015-2333 · Adobe · Reader+5
Abdulaziz Hariri
+1
·
Published
2015-10-13
·
Updated
2021-09-08
·
CVE-2015-5583
CVSS v2.0
4.3
Medium
| Vector | AV:N/AC:M/Au:N/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Adobe Acrobat versions (affected versions not specified)
Adobe Reader versions (affected versions not specified)
Adobe Flash Player versions (affected versions not specified)
Adobe Integrated Runtime versions (affected versions not specified)
Adobe Acrobat Document Cloud versions (affected versions not specified)
Adobe Reader Document Cloud versions (affected versions not specified)
Description
The issue is related to insufficient access control mechanisms in the software, allowing a remote attacker to bypass the sandbox and access protected information by creating a print job on a remote printer. This can lead to sensitive information disclosure.
Recommendations
For Adobe Acrobat, update to a version that addresses the access control mechanism weaknesses.
For Adobe Reader, consider disabling the print functionality to remote printers until a patch is available.
For Adobe Flash Player and Adobe Integrated Runtime, restrict access to sensitive information and avoid using remote printing services until the issue is resolved.
For Adobe Acrobat Document Cloud and Adobe Reader Document Cloud, avoid using the print functionality on remote printers and consider disabling access to sensitive documents until a fix is provided.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Acrobat
Acrobat Document Cloud
Flash Player
Integrated Runtime
Reader
Reader Document Cloud