Rapid7 Vulnerability & Exploit Database

Adobe Acrobat: APSB16-14 (CVE-2016-1090): Security Updates Available for Adobe Acrobat and Reader

Free InsightVM Trial No Credit Card Necessary
Watch Demo See how it all works
Back to Search

Adobe Acrobat: APSB16-14 (CVE-2016-1090): Security Updates Available for Adobe Acrobat and Reader

Severity
7
CVSS
(AV:L/AC:L/Au:N/C:C/I:C/A:C)
Published
05/05/2016
Created
07/25/2018
Added
05/17/2016
Modified
03/28/2022

Description

Untrusted search path vulnerability in Adobe Reader and Acrobat before 11.0.16, Acrobat and Acrobat Reader DC Classic before 15.006.30172, and Acrobat and Acrobat Reader DC Continuous before 15.016.20039 on Windows and OS X allows local users to gain privileges via a Trojan horse resource in an unspecified directory, a different vulnerability than CVE-2016-1087 and CVE-2016-4106.

Solution(s)

  • adobe-acrobat-dc-upgrade-15-006-30172-macosx
  • adobe-acrobat-dc-upgrade-15-006-30172-windows
  • adobe-acrobat-dc-upgrade-15-016-20039-macosx
  • adobe-acrobat-dc-upgrade-15-016-20039-windows
  • adobe-acrobat-reader-dc-upgrade-15-006-30172-macosx
  • adobe-acrobat-reader-dc-upgrade-15-006-30172-windows
  • adobe-acrobat-reader-dc-upgrade-15-016-20039-macosx
  • adobe-acrobat-reader-dc-upgrade-15-016-20039-windows
  • adobe-acrobat-upgrade-11-0-16-macosx
  • adobe-acrobat-upgrade-11-0-16-windows

With Rapid7 live dashboards, I have a clear view of all the assets on my network, which ones can be exploited, and what I need to do in order to reduce the risk in my environment in real-time. No other tool gives us that kind of value and insight.

– Scott Cheney, Manager of Information Security, Sierra View Medical Center

;