CVE-2016-0938
Description
The AcroForm plugin in Adobe Reader and Acrobat before 11.0.14, Acrobat and Acrobat Reader DC Classic before 15.006.30119, and Acrobat and Acrobat Reader DC Continuous before 15.010.20056 on Windows and OS X allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2016-0931, CVE-2016-0933, CVE-2016-0936, CVE-2016-0939, CVE-2016-0942, CVE-2016-0944, CVE-2016-0945, and CVE-2016-0946.
Risk Information
Base Score
8.8
MODERATE
Vector
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
EPSS Score
Exploitation Probability
2.724
Associated Vulnerability
| Vulnerability | OS Platform |
|---|---|
| Multiple vulnerabilities fixed in Adobe Reader 11.0.14 update - All languages (APSB16-02) | Windows |
| Multiple vulnerabilities fixed in Adobe Acrobat 11.0.14 Pro and Standard update - All languages (APSB16-02) | Windows |
| Multiple vulnerabilities fixed in Adobe Reader 11.0.14 update - Multilingual (MUI) installer (APSB16-02) | Windows |
| Multiple vulnerabilities fixed in Adobe Acrobat DC 15.010.20056 | Windows |
| Multiple vulnerabilities fixed in Adobe Acrobat DC 15.006.30119 | Windows |
| Multiple vulnerabilities affected in Acrobat DC 15.009.20077 | Windows |
| Multiple vulnerabilities affected in Acrobat Reader 11.0.9 | Windows |
| Multiple Vulnerabilities are affected in Adobe Acrobat Reader DC MUI 11.0.13 | Windows |
Patch Details
Click to see the patches provided by ManageEngine for this CVE
| Patch ID | Patch Description |
|---|---|
| PATCH-303115 | Adobe Reader 11.0.14 update - All languages (APSB16-02) |
| PATCH-303114 | Adobe Acrobat 11.0.14 Pro and Standard update - All languages (APSB16-02) |
| PATCH-303121 | Adobe Reader 11.0.14 update - Multilingual (MUI) installer (APSB16-02) |
| PATCH-343120 | Adobe Acrobat Reader DC (24.004.20272) |
| PATCH-315460 | Adobe Acrobat DC Pro and Standard (Classic Track) update - All languages (15.006.30527) (APSB20-48) |
| PATCH-343119 | Adobe Acrobat DC Pro and Standard (Continuous Track) update - All languages (24.004.20272) |
| PATCH-315465 | Adobe Acrobat Reader MUI DC (Classic Track) update - All languages (15.006.30527) (APSB20-48) |
| PATCH-343122 | Adobe Acrobat Reader DC MUI (24.004.20272) |
References
https://nvd.nist.gov/vuln/detail/CVE-2023-1234
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2023-1234