vendor:
Acrobat Reader
by:
Reigning Shells
7,5
CVSS
HIGH
Bypass Vulnerability
20
CWE
Product Name: Acrobat Reader
Affected Version From: Adobe Reader and Acrobat 10.x before 10.1.14 and 11.x before 11.0.11
Affected Version To: Adobe Reader and Acrobat 10.x before 10.1.14 and 11.x before 11.0.11
Patch Exists: YES
Related CWE: CVE-2015-3073
CPE: a:adobe:acrobat_reader:10.1.14
Metasploit:
https://www.rapid7.com/db/vulnerabilities/adobe-reader-apsb15-10-CVE-2015-3060/, https://www.rapid7.com/db/vulnerabilities/adobe-reader-apsb15-10-CVE-2015-3061/, https://www.rapid7.com/db/vulnerabilities/adobe-reader-apsb15-10-CVE-2015-3062/, https://www.rapid7.com/db/vulnerabilities/adobe-reader-apsb15-10-CVE-2015-3063/, https://www.rapid7.com/db/vulnerabilities/adobe-reader-apsb15-10-CVE-2015-3064/, https://www.rapid7.com/db/vulnerabilities/adobe-reader-apsb15-10-CVE-2015-3065/, https://www.rapid7.com/db/vulnerabilities/adobe-reader-apsb15-10-CVE-2015-3066/, https://www.rapid7.com/db/vulnerabilities/adobe-reader-apsb15-10-CVE-2015-3067/, https://www.rapid7.com/db/vulnerabilities/adobe-reader-apsb15-10-CVE-2015-3068/, https://www.rapid7.com/db/vulnerabilities/adobe-reader-apsb15-10-CVE-2015-3069/, https://www.rapid7.com/db/vulnerabilities/adobe-reader-apsb15-10-CVE-2015-3071/, https://www.rapid7.com/db/vulnerabilities/adobe-reader-apsb15-10-CVE-2015-3072/, https://www.rapid7.com/db/vulnerabilities/adobe-reader-apsb15-10-CVE-2015-3073/, https://www.rapid7.com/db/vulnerabilities/adobe-reader-apsb15-10-CVE-2015-3074/
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows 7
2015
Adobe Acrobat Reader AFParseDate Javascript API Restrictions Bypass Vulnerability
This vulnerability allows remote attackers to bypass API restrictions on vulnerable installations of Adobe Reader. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within AFParseDate. By creating a specially crafted PDF with specific JavaScript instructions, it is possible to bypass the Javascript API restrictions. A remote attacker could exploit this vulnerability to execute arbitrary code.
Mitigation:
Adobe has released updates to address this vulnerability. Users should update to the latest version of Adobe Reader and Acrobat.