KEVIntel
7.8
CVSS
High

CVE-2023-21608

PUBLISHED

Adobe Acrobat Reader DC resetForm Use-After-Free Remote Code Execution Vulnerability

Exploited in the wild Low complexity
Vendor
Adobe
Product
Acrobat Reader
Published
Jan 18, 2023
EPSS

Description

Adobe Acrobat Reader versions 22.003.20282 (and earlier), 22.003.20281 (and earlier) and 20.005.30418 (and earlier) are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

cisa nessus_scanner

CVSS scores

CVSS v3.1 7.8 High

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Exploitation status

Exploited in the wild

Recorded 2023-10-10 00:00:00 UTC · Source

SSVC decision points

Exploitation
active
Automatable
No
Technical impact
total

Known exploited vulnerability sources

Catalogues that list this CVE as a known exploited vulnerability.

Source Added
CISA Oct 10, 2023

Scanner integrations

Scanner Reference Detected
Nessus https://www.tenable.com/plugins/nessus/169880 Jun 02, 2025

Potential proof of concepts

These PoCs are unverified and could contain malware. Use at your own risk.

Malwareman007/CVE-2023-21608

github · Created 2023-02-13 06:11:40 UTC · 11 stars

Adobe Acrobat Reader - CVE-2023-21608 - Remote Code Execution Exploit

hacksysteam/CVE-2023-21608

github · Created 2023-01-30 12:57:48 UTC · 272 stars

Adobe Acrobat Reader - CVE-2023-21608 - Remote Code Execution Exploit

Timeline

  • CVE ID Reserved

  • CVE Published to Public

  • Added to KEVIntel

  • Detected by Nessus