PT-2016-1938 · Adobe · Acrobat+1

Matthias Kaiser

·

Published

2016-05-05

·

Updated

2016-12-01

·

CVE-2016-1041

CVSS v3.1

10

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Adobe Reader versions (affected versions not specified) Adobe Acrobat versions (affected versions not specified)
Description The issue is related to insufficient access control in Adobe Reader and Adobe Acrobat, allowing a remote attacker to bypass restrictions on JavaScript API execution. This can be achieved through the ANAuthenticateResource Javascript API, which has restrictions that can be bypassed.
Recommendations For Adobe Reader, update to a version that addresses the access control issue, although the specific version is not provided. For Adobe Acrobat, consider disabling the ANAuthenticateResource Javascript API as a temporary workaround until a patch is available. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Improper Access Control

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2016-01271
CVE-2016-1041
ZDI-16-288

Affected Products

Acrobat
Reader