CVE-2016-1090

HIGH

Adobe Reader/Acrobat <11.0.16, DC Classic <15.006.30172, DC Continu...

Title source: llm

Description

Untrusted search path vulnerability in Adobe Reader and Acrobat before 11.0.16, Acrobat and Acrobat Reader DC Classic before 15.006.30172, and Acrobat and Acrobat Reader DC Continuous before 15.016.20039 on Windows and OS X allows local users to gain privileges via a Trojan horse resource in an unspecified directory, a different vulnerability than CVE-2016-1087 and CVE-2016-4106.

Scores

CVSS v3 7.8
EPSS 0.0048
EPSS Percentile 64.9%
Attack Vector LOCAL
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Classification

Status draft

Affected Products (6)

adobe/acrobat < 11.0.15
adobe/acrobat_dc < 15.006.30121
adobe/acrobat_dc < 15.010.20060
adobe/acrobat_reader_dc < 15.006.30121
adobe/acrobat_reader_dc < 15.010.20060
adobe/reader < 11.0.15

Timeline

Published May 11, 2016
Tracked Since Feb 18, 2026