A Sandbox security bypass vulnerability has been identified in version 11.0.8 of Adobe Acrobat Reader, which has not been patched to date, affecting all later versions of the program.
The vulnerability can be exploited under certain circumstances to perform NTFS junction attacks. Theoretically, this weakness could allow a potential attacker to bypass the Sandbox and insert arbitrary files into the filesystem, gaining the same permissions as the user.
James Forshaw, a security researcher at Google, discovered the vulnerability in Sandbox in August, along with a proof-of-concept. The researcher disclosed the vulnerability to the company before it was publicly released, giving Adobe 90 days to release a patch.
Adobe app to version 11.0.9, but the researcher says the issue still exists in the new version. However, it appears the company has taken some steps to ensure users are not at risk.
Forshaw says that the radical changes made to the latest version of Acrobat Reader in terms of application security make it difficult, if not impossible, to exploit the vulnerability.

