CVE-2015-7621 is a use-after-free vulnerability affecting Adobe Reader and Acrobat on Windows and OS X, specifically versions 10.x before 10.1.16, 11.x before 11.0.13, and certain DC Classic and Continuous releases. This flaw allows attackers to execute arbitrary code by crafting a malicious U3D object. The vulnerability has a CVSS score of 6.8, indicating a medium severity with a network attack vector, medium access complexity, and potential for partial confidentiality, integrity, and availability impact. While it is not listed in CISA's KEV catalog and has no known public exploits or significant community discussion, organizations should still apply the vendor-provided patches to mitigate the risk.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 10.0, <= 10.1.15CPE matchmatch criteria | cpe:2.3:a:adobe:acrobat:*:*:*:*:*:*:*:* | ||
>= 11.0.0, <= 11.0.12CPE matchmatch criteria | cpe:2.3:a:adobe:acrobat:*:*:*:*:*:*:*:* | ||
>= 15.006.30060, < 15.006.30094CPE matchmatch criteria | cpe:2.3:a:adobe:acrobat_dc:*:*:*:*:classic:*:*:* | ||
>= 15.008.20082, < 15.009.20069CPE matchmatch criteria | cpe:2.3:a:adobe:acrobat_dc:*:*:*:*:continuous:*:*:* | ||
>= 10.0, <= 10.1.15CPE matchmatch criteria | cpe:2.3:a:adobe:acrobat_reader:*:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:M/Au:N/C:P/I:P/A:P
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.