Junglewise Threat Intelligence

CVE-2023-21608: Adobe Acrobat and Reader Use-After-Free Vulnerability

CVE-2023-21608 · Severity: critical · CVSS 7.8 · Exploited in the wild · Published 2023-10-10

Technologies: Adobe Acrobat, Adobe Reader, Adobe Acrobat Dc, Adobe Flash Player, Adobe Acrobat Reader, Adobe AIR, Adobe Acrobat Reader Dc. Vendors: Adobe.

Executive brief

Adobe Acrobat and Reader are affected by a use-after-free vulnerability that can lead to arbitrary code execution in the context of the current user. Exploitation requires a victim to open a specially crafted malicious file.

Affected products

  • Adobe Acrobat Reader 22.003.20282 (and earlier), 22.003.20281 (and earlier), 20.005.30418 (and earlier)
  • Adobe Acrobat DC 15.008.20082 up to 22.003.20282
  • Adobe Acrobat Reader DC 15.008.20082 up to 22.003.20282

Timeline

  • 2023-01-18: disclosed: NVD Published Date
  • 2023-10-10: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
  • 2023-10-10: exploited: Reported as exploited in the wild

Related threats