Adobe Reader and Acrobat 9.x before 9.3.3, and 8.x before 8.2.3 on Windows and Mac OS X, do not restrict the contents of one text field in the Launch File warning dialog, which makes it easier for remote attackers to trick users into executing an arbitrary local program that was specified in a PDF document, as demonstrated by a text field that claims that the Open button will enable the user to read an encrypted message.
CVSS Details
- CVSS 3.1 Base Score: 8
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Adobe Reader Apsb10 15 | — | — | Apr 12, 2012 | Apr 5, 2010 |
| Adobe Reader Apsb10 17 | — | — | Apr 12, 2012 | Apr 5, 2010 |
| Suse | — | Upgrade acroreadUpgrade acroread-fonts-zh_TWUpgrade acroread-fonts-koUpgrade acroread-fonts-zh_CNUpgrade acroread_jaUpgrade acroread-cmapsUpgrade acroread-fonts-ja | Feb 17, 2015 | Apr 5, 2010 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub