CVE-2015-7622

CRITICAL ⚠ Exploit

Adobe Reader and Acrobat 10.x before 10.1.16 and 11.x before 11.0.13, Acrobat and Acrobat Reader DC Classic before 2015.006.30094, and Acrobat and Acrobat Reader DC Continuous before 2015.009.20069...

Affects 6 products across 3 vendors.

BCS8.91
CVSS 2.010.0
EPSS23.4%
Percentile98th
PatchUnknown
CVSS Vector — Plain English Remotely exploitable over the network, low complexity.
CWE Weakness Definitions
CWE-119: Improper Restriction of Operations within Memory Buffer

Parent class for buffer-related vulnerabilities where operations exceed buffer boundaries.

Related Attack Patterns (CAPEC)
CAPEC-8 Buffer Overflow in an API Call
via CWE-119
CAPEC-9 Buffer Overflow in Local Command-Line Utilities
via CWE-119
CAPEC-10 Buffer Overflow via Environment Variables
via CWE-119
CAPEC-14 Client-side Injection-induced Buffer Overflow
via CWE-119
CAPEC-24 Filter Failure through Buffer Overflow
via CWE-119
Show all 12

Mapping is CWE-to-CAPEC per MITRE CAPEC 3.9.

◆ SAGE Intelligence — CITED Relevance Research Team

Adobe Reader and Acrobat versions prior to specified updates are vulnerable to arbitrary code execution or denial of service due to memory corruption via unspecified vectors.

BSID: BS-2015-GLOBAL-169865-C • Model: /workspace/models/qwen2.5-coder-32b-instruct-bf16 • Confidence: HIGH

Is this CVE in your environment?

BreachSpider monitors your ICS/OT environment for vulnerabilities like this one. No agents or network access required. Free to start.

Check My Environment →
Frequently Asked Questions
What is CVE-2015-7622?
Adobe Reader and Acrobat versions prior to specified updates are vulnerable to arbitrary code execution or denial of service due to memory corruption via unspecified vectors.
What is the CVSS score for CVE-2015-7622?
CVE-2015-7622 has CVSS 10.0 (Critical). Vector: AV:N/AC:L/Au:N/C:C/I:C/A:C. EPSS: 23.4%.
Is CVE-2015-7622 actively exploited?
Public exploit available for CVE-2015-7622. Exploitation risk elevated.
How do I remediate CVE-2015-7622?
Priority: IMMEDIATE.
What systems are affected by CVE-2015-7622?
CVE-2015-7622 affects: Adobe, Adobe, Adobe, Adobe, Apple, Microsoft.
Vulnerability Details
CVE IDCVE-2015-7622
BSIDBS-2015-GLOBAL-169865-C BreachSpider Global ID
CVSS VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Published2015-10-14
Last Modified2026-05-06
ICS Relevance15%
Weakness (CWE)
SourceNVD
Official Description

Adobe Reader and Acrobat 10.x before 10.1.16 and 11.x before 11.0.13, Acrobat and Acrobat Reader DC Classic before 2015.006.30094, and Acrobat and Acrobat Reader DC Continuous before 2015.009.20069 on Windows and OS X allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2015-6685, CVE-2015-6686, CVE-2015-6693, CVE-2015-6694, and CVE-2015-6695.

Source: NIST NVD / MITRE CVE Database

Attack Vector Analysis — CITED Relevance

The vulnerability allows attackers to exploit memory corruption issues in Adobe Reader and Acrobat, potentially leading to arbitrary code execution or a denial of service. The exact attack vectors are unspecified, but they involve improper handling of PDF files.

Exploitation Likelihood: CRITICAL

Affected Products
VendorProductFixed Version
Adobe Acrobat Reader
Adobe Acrobat
Adobe Acrobat Dc
Adobe Acrobat Reader Dc
Apple Macos
Microsoft Windows
Remediation

No patch URL on record. Monitor vendor security advisories directly.

Threat Intelligence
● Threat Intelligence Validated: August 2026 | Threat Age: 3946 Days
CISA KEVNot in KEV catalog
Public Exploit⚠ AvailableReference
PoC CodeNot confirmed
SAGE Enrichment Record — provenance & audit hash
Model/workspace/models/qwen2.5-coder-32b-instruct-bf16
ConfidenceHIGH
Enriched At2026-05-24
Related CVEs affecting Adobe
CVE-2014-0590 10.0 Adobe Flash Player before 13.0.0.252 and 14.x and 15.x before 15.0.0.223 on W... CVE-2026-48281 10.0 ColdFusion versions 2025.9, 2023.20 and earlier are affected by an Improper I... CVE-2013-3324 10.0 Adobe Flash Player before 10.3.183.86 and 11.x before 11.7.700.202 on Windows... CVE-2004-1153 10.0 Format string vulnerability in Adobe Acrobat Reader 6.0.0 through 6.0.2 allow... CVE-2015-5101 10.0 Use-after-free vulnerability in Adobe Reader and Acrobat 10.x before 10.1.15 ...
View all Adobe CVEs →

Critical Severity - Know Your Exposure

A CVSS 10.0 vulnerability in your ICS environment cannot wait. BreachSpider maps critical CVEs to your specific assets and tells you what to fix first.

Check Your Assets Free →