Junglewise Threat Intelligence

CVE-2023-26369: Adobe Acrobat and Reader Out-of-Bounds Write Vulnerability

CVE-2023-26369 · Severity: critical · CVSS 7.8 · Exploited in the wild · Published 2023-09-14

Technologies: Adobe Acrobat, Adobe Acrobat Reader, Adobe Reader, Adobe Flash Player, Adobe AIR, Adobe Acrobat Dc. Vendors: Adobe.

Executive brief

Adobe Acrobat and Reader are affected by an out-of-bounds write vulnerability that can lead to arbitrary code execution. Exploitation requires a victim to open a specially crafted malicious file, allowing code execution in the context of the current user.

Affected products

  • Adobe Acrobat Reader 23.003.20284 (and earlier), 20.005.30516 (and earlier), 20.005.30514 (and earlier)
  • Adobe Acrobat DC versions from 15.007.20033 up to 23.006.20320

Timeline

  • 2023-09-13: disclosed
  • 2023-09-14: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
  • 2023-09-14: advisory

Related threats