Intrusion Prevention

Adobe.Reader.Privilege.API.Calls.Information.Disclosure

Description

This indicates an attack attempt to exploit an Information Disclosure vulnerability in Adobe Reader and Acrobat.
The vulnerability is caused by a lack of sanitizing of privilege API calls from a non privilege context. A remote attacker can exploit this to gain unauthorized access to sensitive information.

Affected Products

Adobe Reader XI (11.0.06) and earlier 11.x versions for Windows and Macintosh
Adobe Reader X (10.1.9) and earlier 10.x versions for Windows and Macintosh
Adobe Acrobat XI (11.0.06) and earlier 11.x versions for Windows and Macintosh
Adobe Acrobat X (10.1.9) and earlier 10.x versions for Windows and Macintosh

Impact

Information Disclosure: Remote attackers can gain sensitive information from vulnerable systems.

Recommended Actions

Upgrade to the latest version available from the website.
http://helpx.adobe.com/security/products/reader/apsb14-15.html

CVE References

CVE-2014-0521