ID

VAR-201605-0155


CVE

CVE-2016-1087


TITLE

Windows and Mac OS X Run on Adobe Reader and Acrobat Vulnerability gained in

Trust: 0.8

sources: JVNDB: JVNDB-2016-002651

DESCRIPTION

Untrusted search path vulnerability in Adobe Reader and Acrobat before 11.0.16, Acrobat and Acrobat Reader DC Classic before 15.006.30172, and Acrobat and Acrobat Reader DC Continuous before 15.016.20039 on Windows and OS X allows local users to gain privileges via a Trojan horse resource in an unspecified directory, a different vulnerability than CVE-2016-1090 and CVE-2016-4106. This vulnerability CVE-2016-1090 and CVE-2016-4106 Is a different vulnerability. Supplementary information : CWE Vulnerability type by CWE-426: Untrusted Search Path ( Unreliable search path ) Has been identified. http://cwe.mitre.org/data/definitions/426.htmlA local user may be able to obtain permissions through Trojan horse resources in unspecified directories. Adobe Reader and Acrobat are prone to multiple remote code-execution vulnerabilities. An attacker can exploit these issues to execute arbitrary code in the context of the user running the affected application. Failed exploit attempts will likely result in denial-of-service conditions. Adobe Acrobat DC, etc. are all products of Adobe (Adobe) in the United States. Acrobat DC is a desktop PDF solution; Acrobat Reader DC is a set of tools for viewing, printing and annotating PDF. Security flaws exist in several Adobe products

Trust: 1.98

sources: NVD: CVE-2016-1087 // JVNDB: JVNDB-2016-002651 // BID: 90513 // VULHUB: VHN-89689

AFFECTED PRODUCTS

vendor:adobemodel:acrobat dcscope:lteversion:15.006.30121

Trust: 1.0

vendor:adobemodel:acrobat dcscope:lteversion:15.010.20060

Trust: 1.0

vendor:adobemodel:acrobat reader dcscope:lteversion:15.006.30121

Trust: 1.0

vendor:adobemodel:readerscope:lteversion:11.0.15

Trust: 1.0

vendor:adobemodel:acrobat reader dcscope:lteversion:15.010.20060

Trust: 1.0

vendor:adobemodel:acrobatscope:lteversion:11.0.15

Trust: 1.0

vendor:adobemodel:acrobatscope:ltversion:xi desktop 11.0.16 (windows/macintosh)

Trust: 0.8

vendor:adobemodel:acrobat dcscope:ltversion:classic 15.006.30172 (windows/macintosh)

Trust: 0.8

vendor:adobemodel:acrobat dcscope:ltversion:continuous track 15.016.20039 (windows/macintosh)

Trust: 0.8

vendor:adobemodel:acrobat reader dcscope:ltversion:classic 15.006.30172 (windows/macintosh)

Trust: 0.8

vendor:adobemodel:acrobat reader dcscope:ltversion:continuous track 15.016.20039 (windows/macintosh)

Trust: 0.8

vendor:adobemodel:readerscope:ltversion:xi desktop 11.0.16 (windows/macintosh)

Trust: 0.8

vendor:microsoftmodel:windowsscope: - version: -

Trust: 0.6

sources: JVNDB: JVNDB-2016-002651 // CNNVD: CNNVD-201605-286 // NVD: CVE-2016-1087

CVSS

SEVERITY

CVSSV2

CVSSV3

nvd@nist.gov: CVE-2016-1087
value: HIGH

Trust: 1.0

NVD: CVE-2016-1087
value: HIGH

Trust: 0.8

CNNVD: CNNVD-201605-286
value: HIGH

Trust: 0.6

VULHUB: VHN-89689
value: HIGH

Trust: 0.1

nvd@nist.gov: CVE-2016-1087
severity: HIGH
baseScore: 7.2
vectorString: AV:L/AC:L/AU:N/C:C/I:C/A:C
accessVector: LOCAL
accessComplexity: LOW
authentication: NONE
confidentialityImpact: COMPLETE
integrityImpact: COMPLETE
availabilityImpact: COMPLETE
exploitabilityScore: 3.9
impactScore: 10.0
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 1.8

VULHUB: VHN-89689
severity: HIGH
baseScore: 7.2
vectorString: AV:L/AC:L/AU:N/C:C/I:C/A:C
accessVector: LOCAL
accessComplexity: LOW
authentication: NONE
confidentialityImpact: COMPLETE
integrityImpact: COMPLETE
availabilityImpact: COMPLETE
exploitabilityScore: 3.9
impactScore: 10.0
acInsufInfo: NONE
obtainAllPrivilege: NONE
obtainUserPrivilege: NONE
obtainOtherPrivilege: NONE
userInteractionRequired: NONE
version: 2.0

Trust: 0.1

nvd@nist.gov: CVE-2016-1087
baseSeverity: HIGH
baseScore: 7.8
vectorString: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
attackVector: LOCAL
attackComplexity: LOW
privilegesRequired: LOW
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: HIGH
integrityImpact: HIGH
availabilityImpact: HIGH
exploitabilityScore: 1.8
impactScore: 5.9
version: 3.0

Trust: 1.8

sources: VULHUB: VHN-89689 // JVNDB: JVNDB-2016-002651 // CNNVD: CNNVD-201605-286 // NVD: CVE-2016-1087

PROBLEMTYPE DATA

problemtype:NVD-CWE-Other

Trust: 1.0

problemtype:CWE-Other

Trust: 0.8

sources: JVNDB: JVNDB-2016-002651 // NVD: CVE-2016-1087

THREAT TYPE

local

Trust: 0.6

sources: CNNVD: CNNVD-201605-286

TYPE

lack of information

Trust: 0.6

sources: CNNVD: CNNVD-201605-286

CONFIGURATIONS

sources: JVNDB: JVNDB-2016-002651

PATCH

title:APSB16-14url:https://helpx.adobe.com/security/products/acrobat/apsb16-14.html

Trust: 0.8

title:APSB16-14url:https://helpx.adobe.com/jp/security/products/reader/apsb16-14.html

Trust: 0.8

title:アドビ システムズ社 Adobe Reader の脆弱性に関するお知らせurl:http://www.fmworld.net/biz/common/adobe/20160512.html

Trust: 0.8

title:Multiple Adobe Product security vulnerabilitiesurl:http://www.cnnvd.org.cn/web/xxk/bdxqById.tag?id=61604

Trust: 0.6

sources: JVNDB: JVNDB-2016-002651 // CNNVD: CNNVD-201605-286

EXTERNAL IDS

db:NVDid:CVE-2016-1087

Trust: 2.8

db:BIDid:90513

Trust: 1.4

db:SECTRACKid:1035828

Trust: 1.1

db:JVNDBid:JVNDB-2016-002651

Trust: 0.8

db:CNNVDid:CNNVD-201605-286

Trust: 0.7

db:AUSCERTid:ESB-2016.1146

Trust: 0.6

db:VULHUBid:VHN-89689

Trust: 0.1

sources: VULHUB: VHN-89689 // BID: 90513 // JVNDB: JVNDB-2016-002651 // CNNVD: CNNVD-201605-286 // NVD: CVE-2016-1087

REFERENCES

url:https://helpx.adobe.com/security/products/acrobat/apsb16-14.html

Trust: 1.7

url:http://www.securityfocus.com/bid/90513

Trust: 1.1

url:http://www.securitytracker.com/id/1035828

Trust: 1.1

url:http://cve.mitre.org/cgi-bin/cvename.cgi?name=cve-2016-1087

Trust: 0.8

url:https://www.ipa.go.jp/security/ciadr/vul/20160511-adobereader.html

Trust: 0.8

url:https://www.jpcert.or.jp/at/2016/at160023.html

Trust: 0.8

url:http://web.nvd.nist.gov/view/vuln/detail?vulnid=cve-2016-1087

Trust: 0.8

url:http://www.npa.go.jp/cyberpolice/topics/?seq=18377

Trust: 0.8

url:https://www.auscert.org.au/render.html?it=34330

Trust: 0.6

url:http://www.adobe.com

Trust: 0.3

url:http://get.adobe.com/reader/

Trust: 0.3

sources: VULHUB: VHN-89689 // BID: 90513 // JVNDB: JVNDB-2016-002651 // CNNVD: CNNVD-201605-286 // NVD: CVE-2016-1087

CREDITS

Anand Bhat

Trust: 0.6

sources: CNNVD: CNNVD-201605-286

SOURCES

db:VULHUBid:VHN-89689
db:BIDid:90513
db:JVNDBid:JVNDB-2016-002651
db:CNNVDid:CNNVD-201605-286
db:NVDid:CVE-2016-1087

LAST UPDATE DATE

2025-04-13T23:02:57.675000+00:00


SOURCES UPDATE DATE

db:VULHUBid:VHN-89689date:2016-12-01T00:00:00
db:BIDid:90513date:2016-05-10T00:00:00
db:JVNDBid:JVNDB-2016-002651date:2016-05-17T00:00:00
db:CNNVDid:CNNVD-201605-286date:2016-05-11T00:00:00
db:NVDid:CVE-2016-1087date:2025-04-12T10:46:40.837

SOURCES RELEASE DATE

db:VULHUBid:VHN-89689date:2016-05-11T00:00:00
db:BIDid:90513date:2016-05-10T00:00:00
db:JVNDBid:JVNDB-2016-002651date:2016-05-17T00:00:00
db:CNNVDid:CNNVD-201605-286date:2016-05-11T00:00:00
db:NVDid:CVE-2016-1087date:2016-05-11T10:59:58.343