7.2
CVSSv2

CVE-2015-5090

Published: 15/07/2015 Updated: 08/09/2021
CVSS v2 Base Score: 7.2 | Impact Score: 10 | Exploitability Score: 3.9
VMScore: 641
Vector: AV:L/AC:L/Au:N/C:C/I:C/A:C

Vulnerability Summary

Adobe Reader and Acrobat 10.x prior to 10.1.15 and 11.x prior to 11.0.12, Acrobat and Acrobat Reader DC Classic prior to 2015.006.30060, and Acrobat and Acrobat Reader DC Continuous prior to 2015.008.20082 on Windows and OS X allow malicious users to bypass intended access restrictions and perform a transition from Low Integrity to Medium Integrity via unspecified vectors, a different vulnerability than CVE-2015-4446 and CVE-2015-5106.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

adobe acrobat

adobe acrobat_dc

adobe acrobat_reader

adobe acrobat_reader_dc

Github Repositories

public bugs/proof of concepts

Bugs Public proof of concepts/bugs/weaponized exploits/etc etc CVE-2015-5090 Adobe Reader/Acrobat Pro privilege escalation in <= 11010 CVE-2018-11072 Dell Digital Delivery LPE Using the PoC, you'll need to drop a DLL under the appropriate entitlement folder in %ProgramData% The included PoC simply triggers the entitlement reinstallation (see ExampleProject pr