Executive brief
Adobe Acrobat and Reader are affected by a use-after-free vulnerability that can lead to arbitrary code execution in the context of the current user. Exploitation requires a victim to open a specially crafted malicious file.
Affected products
- Adobe Acrobat Reader 22.003.20282 (and earlier), 22.003.20281 (and earlier), 20.005.30418 (and earlier)
- Adobe Acrobat DC 15.008.20082 up to 22.003.20282
- Adobe Acrobat Reader DC 15.008.20082 up to 22.003.20282
Timeline
- 2023-01-18: disclosed: NVD Published Date
- 2023-10-10: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
- 2023-10-10: exploited: Reported as exploited in the wild