HIGH

CVE-2023-21608

Adobe Acrobat Dc 2023-01-18 CVSS v3.1
CVSS
7.8
KEV

Description

Adobe Acrobat Reader versions 22.003.20282 (and earlier), 22.003.20281 (and earlier) and 20.005.30418 (and earlier) are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

Summary dbcve.org

Adobe Acrobat Reader contains a Use After Free vulnerability where memory is accessed after being freed, allowing an attacker to execute arbitrary code in the context of the current user. Exploitation requires the victim to open a specially crafted malicious PDF file.

Mitigation

Update Adobe Acrobat Reader to a patched version beyond 22.003.20282, 22.003.20281, or 20.005.30418. Users should avoid opening untrusted PDF files from unknown sources.

Weakness (CWE)

CWE-416 Use After Free

EPSS Score

61.48%
Probability of exploitation in next 30 days
99.1th percentile

References

View on dbcve.org
Base CVE data derived from NVD (public domain). Enrichment by dbcve.org (CC-BY-4.0). Fetched via API.
Back to CVE