CVE-2015-3073 : Détail

CVE-2015-3073

A01-Broken Access Control
1.25%V3
Network
2015-05-13
08h00 +00:00
2016-12-30
14h57 +00:00
Notifications pour un CVE
Restez informé de toutes modifications pour un CVE spécifique.
Gestion des notifications

Descriptions du CVE

Adobe Reader and Acrobat 10.x before 10.1.14 and 11.x before 11.0.11 on Windows and OS X allow attackers to bypass intended restrictions on JavaScript API execution via unspecified vectors, a different vulnerability than CVE-2015-3060, CVE-2015-3061, CVE-2015-3062, CVE-2015-3063, CVE-2015-3064, CVE-2015-3065, CVE-2015-3066, CVE-2015-3067, CVE-2015-3068, CVE-2015-3069, CVE-2015-3071, CVE-2015-3072, and CVE-2015-3074.

Informations du CVE

Faiblesses connexes

CWE-ID Nom de la faiblesse Source
CWE-284 Improper Access Control
The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.

Métriques

Métriques Score Gravité CVSS Vecteur Source
V2 10 AV:N/AC:L/Au:N/C:C/I:C/A:C [email protected]

EPSS

EPSS est un modèle de notation qui prédit la probabilité qu'une vulnérabilité soit exploitée.

Score EPSS

Le modèle EPSS produit un score de probabilité compris entre 0 et 1 (0 et 100 %). Plus la note est élevée, plus la probabilité qu'une vulnérabilité soit exploitée est grande.

Percentile EPSS

Le percentile est utilisé pour classer les CVE en fonction de leur score EPSS. Par exemple, une CVE dans le 95e percentile selon son score EPSS est plus susceptible d'être exploitée que 95 % des autres CVE. Ainsi, le percentile sert à comparer le score EPSS d'une CVE par rapport à d'autres CVE.

Informations sur l'Exploit

Exploit Database EDB-ID : 38344

Date de publication : 2015-09-27 22h00 +00:00
Auteur : Reigning Shells
EDB Vérifié : No

# Title: Adobe Acrobat Reader AFParseDate Javascript API Restrictions Bypass Vulnerability # Date: 09/28/2015 # Author: Reigning Shells, based off PoC published by Zero Day Initiative # Vendor Homepage: adobe.com # Version: Adobe Reader and Acrobat 10.x before 10.1.14 and 11.x before 11.0.11 on Windows and OS X are vulnerable. # Tested on: Adobe Acrobat 11.0.10 on Windows 7 # CVE : CVE-2015-3073 This vulnerability allows remote attackers to bypass API restrictions on vulnerable installations of Adobe Reader. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within AFParseDate. By creating a specially crafted PDF with specific JavaScript instructions, it is possible to bypass the Javascript API restrictions. A remote attacker could exploit this vulnerability to execute arbitrary code. Adobe Reader and Acrobat 10.x before 10.1.14 and 11.x before 11.0.11 on Windows and OS X are vulnerable. Notes: The code assumes you attached a DLL named exploit.txt to the PDF document to get around attachment security restrictions. Acrobat will execute updaternotifications.dll if it's in the same directory as the Acrobat executable or the same directory as the document being opened. Credit for discovery and the initial POC that illustrates code being executed in the privileged context (launching a URL) goes to the Zero Day Initiative. Code: https://github.com/reigningshells/CVE-2015-3073/blob/master/exploit.js https://gitlab.com/exploit-database/exploitdb-bin-sploits/-/raw/main/bin-sploits/38344.zip

Products Mentioned

Configuraton 0

Adobe>>Acrobat >> Version 10.1.0

Adobe>>Acrobat >> Version 10.1.1

Adobe>>Acrobat >> Version 10.1.2

Adobe>>Acrobat >> Version 10.1.3

Adobe>>Acrobat >> Version 10.1.4

Adobe>>Acrobat >> Version 10.1.5

Adobe>>Acrobat >> Version 10.1.6

Adobe>>Acrobat >> Version 10.1.7

Adobe>>Acrobat >> Version 10.1.8

Adobe>>Acrobat >> Version 10.1.9

Adobe>>Acrobat >> Version 10.1.10

Adobe>>Acrobat >> Version 10.1.11

Adobe>>Acrobat >> Version 10.1.12

Adobe>>Acrobat >> Version 10.1.13

Adobe>>Acrobat >> Version 11.0.0

Adobe>>Acrobat >> Version 11.0.1

Adobe>>Acrobat >> Version 11.0.2

Adobe>>Acrobat >> Version 11.0.3

Adobe>>Acrobat >> Version 11.0.4

Adobe>>Acrobat >> Version 11.0.5

Adobe>>Acrobat >> Version 11.0.6

Adobe>>Acrobat >> Version 11.0.7

Adobe>>Acrobat >> Version 11.0.8

Adobe>>Acrobat >> Version 11.0.9

Adobe>>Acrobat >> Version 11.0.10

Apple>>Mac_os_x >> Version *

Microsoft>>Windows >> Version *

Configuraton 0

Adobe>>Acrobat_reader >> Version 10.1.0

Adobe>>Acrobat_reader >> Version 10.1.1

Adobe>>Acrobat_reader >> Version 10.1.2

Adobe>>Acrobat_reader >> Version 10.1.3

Adobe>>Acrobat_reader >> Version 10.1.4

Adobe>>Acrobat_reader >> Version 10.1.5

Adobe>>Acrobat_reader >> Version 10.1.6

Adobe>>Acrobat_reader >> Version 10.1.7

Adobe>>Acrobat_reader >> Version 10.1.8

Adobe>>Acrobat_reader >> Version 10.1.9

Adobe>>Acrobat_reader >> Version 10.1.10

Adobe>>Acrobat_reader >> Version 10.1.11

Adobe>>Acrobat_reader >> Version 10.1.12

Adobe>>Acrobat_reader >> Version 10.1.13

Adobe>>Acrobat_reader >> Version 11.0.0

Adobe>>Acrobat_reader >> Version 11.0.1

Adobe>>Acrobat_reader >> Version 11.0.2

Adobe>>Acrobat_reader >> Version 11.0.3

Adobe>>Acrobat_reader >> Version 11.0.4

Adobe>>Acrobat_reader >> Version 11.0.5

Adobe>>Acrobat_reader >> Version 11.0.6

Adobe>>Acrobat_reader >> Version 11.0.7

Adobe>>Acrobat_reader >> Version 11.0.8

Adobe>>Acrobat_reader >> Version 11.0.9

Adobe>>Acrobat_reader >> Version 11.0.10

Apple>>Mac_os_x >> Version *

Microsoft>>Windows >> Version *

Références

http://www.securityfocus.com/bid/74604
Tags : vdb-entry, x_refsource_BID
http://www.securitytracker.com/id/1032284
Tags : vdb-entry, x_refsource_SECTRACK
https://www.exploit-db.com/exploits/38344/
Tags : exploit, x_refsource_EXPLOIT-DB