Adobe Reader and Acrobat before 11.0.14, Acrobat and Acrobat Reader DC Classic before 15.006.30119, and Acrobat and Acrobat Reader DC Continuous before 15.010.20056 on Windows and OS X mishandle the Global object, which allows attackers to bypass JavaScript API execution restrictions via unspecified vectors.
Weaknesses in this category are related to the management of permissions, privileges, and other security features that are used to perform access control.
Link | Tags |
---|---|
http://zerodayinitiative.com/advisories/ZDI-16-012 | third party advisory vdb entry |
http://www.securitytracker.com/id/1034646 | third party advisory vdb entry |
https://helpx.adobe.com/security/products/acrobat/apsb16-02.html | patch vendor advisory |