CVE-2016-1112
9.8
CRITICAL · CVSS 3.0 · EPSS 4.4% (pctl 91)
In your normal cycle
Critical by CVSS (9.8), but no sign of active exploitation.
Description
Adobe Reader and Acrobat before 11.0.16, Acrobat and Acrobat Reader DC Classic before 15.006.30172, and Acrobat and Acrobat Reader DC Continuous before 15.016.20039 on Windows and OS X allow attackers to obtain sensitive information via unspecified vectors.
Scoring
| CVSS | 9.8 (CRITICAL, v3.0) |
|---|---|
| Vector | CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
| EPSS | 4.37% — more likely to be exploited than 91% of all CVEs |
| Weakness | CWE-200 |
| On CISA KEV | no |
| Public exploit | none known |
| Published | 2016-05-11 |
| Last modified | 2026-06-17 |
Affected (6)
| Vendor | Product |
|---|---|
| adobe | acrobat |
| adobe | acrobat dc |
| adobe | acrobat reader dc |
| adobe | reader |
| apple | mac os x |
| microsoft | windows |
References
→ the Explorer · watch your stack · NVD