CVE-2016-1008

high

Description

Untrusted search path vulnerability in Adobe Reader and Acrobat before 11.0.15, Acrobat and Acrobat Reader DC Classic before 15.006.30121, and Acrobat and Acrobat Reader DC Continuous before 15.010.20060 on Windows and OS X allows local users to gain privileges via a Trojan horse DLL in an unspecified directory.

References

https://helpx.adobe.com/security/products/acrobat/apsb16-09.html

http://www.zerodayinitiative.com/advisories/ZDI-16-190

http://www.securitytracker.com/id/1035199

http://www.securityfocus.com/bid/84216

Details

Source: Mitre, NVD

Published: 2016-03-09

Updated: 2016-12-03

Risk Information

CVSS v2

Base Score: 7.2

Vector: CVSS2#AV:L/AC:L/Au:N/C:C/I:C/A:C

Severity: High

CVSS v3

Base Score: 8.4

Vector: CVSS:3.0/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Severity: High