Vulnerabilities > CVE-2011-1353 - Local Privilege Escalation vulnerability in Adobe Acrobat and Reader

047910
CVSS 6.9 - MEDIUM
Attack vector
LOCAL
Attack complexity
MEDIUM
Privileges required
NONE
Confidentiality impact
COMPLETE
Integrity impact
COMPLETE
Availability impact
COMPLETE
local
adobe
microsoft
nessus

Summary

Unspecified vulnerability in Adobe Reader 10.x before 10.1.1 on Windows allows local users to gain privileges via unknown vectors.

Nessus

  • NASL familySuSE Local Security Checks
    NASL idSUSE_11_ACROREAD-111111.NASL
    descriptionacrobat reader was updated to version 9.4.6 to fix several security issues. (CVE-2011-1353 / CVE-2011-2431 / CVE-2011-2432 / CVE-2011-2433 / CVE-2011-2434 / CVE-2011-2435 / CVE-2011-2436 / CVE-2011-2437 / CVE-2011-2438 / CVE-2011-2439 / CVE-2011-2440 / CVE-2011-2441 / CVE-2011-2442)
    last seen2020-06-01
    modified2020-06-02
    plugin id57087
    published2011-12-13
    reporterThis script is Copyright (C) 2011-2019 Tenable Network Security, Inc.
    sourcehttps://www.tenable.com/plugins/nessus/57087
    titleSuSE 11.1 Security Update : Acrobat Reader (SAT Patch Number 5412)
  • NASL familySuSE Local Security Checks
    NASL idSUSE_11_4_ACROREAD-111111.NASL
    descriptionacrobat reader was updated to version 9.4.6 to fix several security issues (CVE-2011-1353, CVE-2011-2431, CVE-2011-2432, CVE-2011-2433, CVE-2011-2434, CVE-2011-2435, CVE-2011-2436, CVE-2011-2437, CVE-2011-2438, CVE-2011-2439, CVE-2011-2440, CVE-2011-2441, CVE-2011-2442)
    last seen2020-06-01
    modified2020-06-02
    plugin id75783
    published2014-06-13
    reporterThis script is Copyright (C) 2014-2019 and is owned by Tenable, Inc. or an Affiliate thereof.
    sourcehttps://www.tenable.com/plugins/nessus/75783
    titleopenSUSE Security Update : acroread (openSUSE-SU-2011:1238-1)
  • NASL familyWindows
    NASL idADOBE_READER_APSB11-24.NASL
    descriptionThe version of Adobe Reader installed on the remote Windows host is earlier than 10.1.1 / 9.4.6 / 8.3.1. It is, therefore, potentially affected by the following vulnerabilities : - An unspecified error exists that allows local privilege escalation attacks. (CVE-2011-1353) - An unspecified error exists that can allow an attacker to bypass security leading to code execution. (CVE-2011-2431) - Several errors exist that allow buffer overflows leading to code execution. (CVE-2011-2432, CVE-2011-2435) - Several errors exist that allow heap overflows leading to code execution. (CVE-2011-2433, CVE-2011-2434, CVE-2011-2436, CVE-2011-2437) - Several errors exist that allow stack overflows leading to code execution. (CVE-2011-2438) - An error exists that can allow memory leaks leading to code execution. (CVE-2011-2439) - A use-after-free error exists that can allow code exection. (CVE-2011-2440) - Several errors exist in the
    last seen2020-06-01
    modified2020-06-02
    plugin id56198
    published2011-09-14
    reporterThis script is Copyright (C) 2011-2018 Tenable Network Security, Inc.
    sourcehttps://www.tenable.com/plugins/nessus/56198
    titleAdobe Reader < 10.1.1 / 9.4.6 / 8.3.1 Multiple Vulnerabilities (APSB11-21, APSB11-24)
  • NASL familyFreeBSD Local Security Checks
    NASL idFREEBSD_PKG_FA2F386F481411E189B4001EC9578670.NASL
    descriptionThe Adobe Security Team reports : An unspecified vulnerability in the U3D component allows remote attackers to execute arbitrary code (or cause a denial of service attack) via unknown vectors. A heap-based buffer overflow allows attackers to execute arbitrary code via unspecified vectors.
    last seen2020-06-01
    modified2020-06-02
    plugin id57705
    published2012-01-27
    reporterThis script is Copyright (C) 2012-2018 and is owned by Tenable, Inc. or an Affiliate thereof.
    sourcehttps://www.tenable.com/plugins/nessus/57705
    titleFreeBSD : acroread9 -- Multiple Vulnerabilities (fa2f386f-4814-11e1-89b4-001ec9578670)
  • NASL familySuSE Local Security Checks
    NASL idSUSE_11_3_ACROREAD-111111.NASL
    descriptionacrobat reader was updated to version 9.4.6 to fix several security issues (CVE-2011-1353, CVE-2011-2431, CVE-2011-2432, CVE-2011-2433, CVE-2011-2434, CVE-2011-2435, CVE-2011-2436, CVE-2011-2437, CVE-2011-2438, CVE-2011-2439, CVE-2011-2440, CVE-2011-2441, CVE-2011-2442)
    last seen2020-06-01
    modified2020-06-02
    plugin id75422
    published2014-06-13
    reporterThis script is Copyright (C) 2014-2019 and is owned by Tenable, Inc. or an Affiliate thereof.
    sourcehttps://www.tenable.com/plugins/nessus/75422
    titleopenSUSE Security Update : acroread (openSUSE-SU-2011:1238-1)
  • NASL familyMacOS X Local Security Checks
    NASL idMACOSX_ADOBE_READER_APSB11-24.NASL
    descriptionThe version of Adobe Reader installed on the remote Mac OS X host is prior to 10.1.1, 9.4.6, or 8.3.1. It is, therefore, affected by the following vulnerabilities : - An unspecified error exists that allows an attacker to bypass security restrictions, resulting in code execution. (CVE-2011-2431) - Multiple buffer overflow conditions exists that allow an attacker to execute arbitrary code. (CVE-2011-2432, CVE-2011-2435) - Multiple heap overflow conditions exist that allow an attacker to execute arbitrary code. (CVE-2011-2433, CVE-2011-2434, CVE-2011-2436, CVE-2011-2437) - Multiple stack overflow conditions exist that allow an attacker to execute arbitrary code. (CVE-2011-2438) - An error exists related to memory leak issues that allows an attacker to execute arbitrary code. (CVE-2011-2439) - A use-after-free error exists that allows an attacker to execute arbitrary code. (CVE-2011-2440) - Multiple errors exist in the CoolType.dll library that can allow stack overflow conditions, resulting in code execution. (CVE-2011-2441) - A logic error exists that allows an attacker to execute arbitrary code. (CVE-2011-2442) - Multiple vulnerabilities exist, as noted in APSB11-21, that can allow an attacker to take control of the affected system or cause the application to crash. (CVE-2011-2130, CVE-2011-2134, CVE-2011-2135, CVE-2011-2136, CVE-2011-2137, CVE-2011-2138, CVE-2011-2139, CVE-2011-2140, CVE-2011-2414, CVE-2011-2415, CVE-2011-2416, CVE-2011-2417, CVE-2011-2425, CVE-2011-2424) Note that Nessus has not tested for these issues but has instead relied only on the application
    last seen2020-06-01
    modified2020-06-02
    plugin id56199
    published2011-09-14
    reporterThis script is Copyright (C) 2011-2018 Tenable Network Security, Inc.
    sourcehttps://www.tenable.com/plugins/nessus/56199
    titleAdobe Reader < 10.1.1 / 9.4.6 / 8.3.1 Multiple Vulnerabilities (APSB11-21, APSB11-24, APSB11-26) (Mac OS X)
  • NASL familySuSE Local Security Checks
    NASL idOPENSUSE-2011-54.NASL
    descriptionacrobat reader was updated to version 9.4.6 to fix several security issues
    last seen2020-06-01
    modified2020-06-02
    plugin id74527
    published2014-06-13
    reporterThis script is Copyright (C) 2014-2019 Tenable Network Security, Inc.
    sourcehttps://www.tenable.com/plugins/nessus/74527
    titleopenSUSE Security Update : acroread (openSUSE-2011-54)
  • NASL familySuSE Local Security Checks
    NASL idSUSE_ACROREAD-7833.NASL
    descriptionAcrobat reader was updated to version 9.4.6 to fix several security issues. (CVE-2011-1353 / CVE-2011-2431 / CVE-2011-2432 / CVE-2011-2433 / CVE-2011-2434 / CVE-2011-2435 / CVE-2011-2436 / CVE-2011-2437 / CVE-2011-2438 / CVE-2011-2439 / CVE-2011-2440 / CVE-2011-2441 / CVE-2011-2442)
    last seen2020-06-01
    modified2020-06-02
    plugin id57154
    published2011-12-13
    reporterThis script is Copyright (C) 2011-2019 Tenable Network Security, Inc.
    sourcehttps://www.tenable.com/plugins/nessus/57154
    titleSuSE 10 Security Update : Acrobat Reader (ZYPP Patch Number 7833)

Oval

accepted2013-02-11T04:00:59.144-05:00
classvulnerability
contributors
  • nameScott Quint
    organizationDTCC
  • nameSergey Artykhov
    organizationALTX-SOFT
definition_extensions
commentAdobe Reader 10.x is installed
ovaloval:org.mitre.oval:def:12283
descriptionUnspecified vulnerability in Adobe Reader 10.x before 10.1.1 on Windows allows local users to gain privileges via unknown vectors.
familywindows
idoval:org.mitre.oval:def:14177
statusaccepted
submitted2011-11-04T14:33:09.000-05:00
titleUnspecified vulnerability in Adobe Reader 10.x before 10.1.1 on Windows allows local users to gain privileges via unknown vectors.
version6

Seebug

bulletinFamilyexploit
descriptionNo description provided by source.
idSSV:20939
last seen2017-11-19
modified2011-09-18
published2011-09-18
reporterRoot
sourcehttps://www.seebug.org/vuldb/ssvid-20939
titleAdobe Reader X Sandbox Bypass Vulnerability