CVE-2016-6957
published 2016-10-13CVE-2016-6957: Adobe Reader and Acrobat before 11.0.18, Acrobat and Acrobat Reader DC Classic before 15.006.30243, and Acrobat and Acrobat Reader DC Continuous before…
PriorityP345critical9.8CVSS 3.0
AVNACLPRNUINSUCHIHAH
EPSS
5.81%
92.4th percentile
Adobe Reader and Acrobat before 11.0.18, Acrobat and Acrobat Reader DC Classic before 15.006.30243, and Acrobat and Acrobat Reader DC Continuous before 15.020.20039 on Windows and OS X allow attackers to bypass JavaScript API execution restrictions via unspecified vectors.
Affected
6 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| adobe | acrobat | <= 11.0.17 | — |
| adobe | acrobat_dc | <= 15.006.30201 | — |
| adobe | acrobat_dc | <= 15.017.20053 | — |
| adobe | acrobat_reader_dc | <= 15.006.30201 | — |
| adobe | acrobat_reader_dc | <= 15.017.20053 | — |
| adobe | reader | <= 11.0.17 | — |
CVSS provenance
nvdv3.09.8CRITICALCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
nvdv2.010.0CRITICALAV:N/AC:L/Au:N/C:C/I:C/A:C
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No detection rules found.
No public exploits indexed.
Unit42
Palo Alto Networks Discovers Two Adobe Reader Privileged JavaScript Zero-Days
blogs_unit42·2016-10-17·CVSS 9.8
CVE-2016-6957 [CRITICAL] Palo Alto Networks Discovers Two Adobe Reader Privileged JavaScript Zero-Days
Threat Research Center
Threat Research
Vulnerabilities
## Palo Alto Networks Discovers Two Adobe Reader Privileged JavaScript Zero-Days
Gal De Leon
Published: October 17, 2016
Threat Research
Vulnerabilities
Adobe
Adobe Reader
We recently discovered two zero-day vulnerabilities in Adobe Reader. Adobe has since released a patch (on October 6, 2016) to fix these vulnerabilities, which are named CVE-2016-6957 and CVE-2016-6958. These vulnerabilities could allow an attacker to compromise Adobe Reader by bypassing restrictions on JavaScript API execution (CVE-2016-6957) and security provisions that prevent arbitrary execution of scripts such as those written in Python (CVE-2016-6957). In this blog post, I will provide a technical walkthrough of these vulnerabilities, how they can be
Unit42
Palo Alto Networks Discovers Two Adobe Reader Privileged JavaScript Zero-Days
blogs_unit42·2016-10-17·CVSS 9.8
CVE-2016-6957 [CRITICAL] Palo Alto Networks Discovers Two Adobe Reader Privileged JavaScript Zero-Days
We recently discovered two zero-day vulnerabilities in Adobe Reader. Adobe has since released a patch (on October 6, 2016) to fix these vulnerabilities, which are named CVE-2016-6957 and CVE-2016-6958. These vulnerabilities could allow an attacker to compromise Adobe Reader by bypassing restrictions on JavaScript API execution (CVE-2016-6957) and security provisions that prevent arbitrary execution of scripts such as those written in Python (CVE-2016-6957). In this blog post, I will provide a technical walkthrough of these vulnerabilities, how they can be exploited, and how Palo Alto Networks customers are protected.
### JavaScript in PDF Files
PDF file format is quite rich. It allows you to render text, pictures, and even 3D objects. It also contains a JavaScript engine that renders scr
Zscaler
Zscaler discovers Flash Player Vulnerabilities | 10-11-2016
blogs_zscaler
Zscaler discovers Flash Player Vulnerabilities | 10-11-2016
Provide users with seamless, secure, reliable access to applications and data.
Build and run secure cloud apps, enable zero trust cloud connectivity, and protect workloads from data center to cloud.
Provide zero trust connectivity for IoT and OT devices and secure remote access to OT systems.
Provide zero trust site-to-site connectivity and reliable access to B2B apps for partners.
Industry Report
Zscaler: A Leader in the 2025 Gartner® Magic Quadrant™ for Security Service Edge (SSE)
USE CASES
INDUSTRY & MARKET SOLUTIONS
PARTNERS
TECHNOLOGY PARTNERS
Resource Center
Events & Trainings
Security Research & Services
Tools
Community & Support
CXO REVOLUTIONARIES
Amplifying the voices of real-world digital and zero trust pioneers
Discover how it began and where it’s going
Meet o
2016-10-13
Published