Executive brief
Adobe Acrobat and Reader are affected by an out-of-bounds write vulnerability that can lead to arbitrary code execution. Exploitation requires a victim to open a specially crafted malicious file, allowing code execution in the context of the current user.
Affected products
- Adobe Acrobat Reader 23.003.20284 (and earlier), 20.005.30516 (and earlier), 20.005.30514 (and earlier)
- Adobe Acrobat DC versions from 15.007.20033 up to 23.006.20320
Timeline
- 2023-09-13: disclosed
- 2023-09-14: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
- 2023-09-14: advisory