CVE-2023-21608

Confirmed PUBLISHED

Adobe Acrobat Reader DC resetForm Use-After-Free Remote Code Execution Vulnerability

Vendor: Adobe Product: Acrobat Reader
Exploited in the wild PoC available

Recommended Action

Prioritize remediation. Validate affected assets and apply vendor fixes on an accelerated timeline.

Confidence
Confirmed
Exploitation Status
Exploited in the wild
Observed in Sensors
No
Attempts (30d)
Unique Attacker IPs
CISA KEV
In CISA KEV
CVSS / EPSS
7.8 High EPSS 61.5%

At a Glance

Adobe Acrobat Reader versions 22.003.20282 (and earlier), 22.003.20281 (and earlier) and 20.005.30418 (and earlier) are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

cisa nessus_scanner
CVE Published
Jan 18, 2023
Exploitation Reported
Oct 10, 2023
CVSS
7.8 High
EPSS
61.5%
Low complexity Unauthenticated

Affected Versions

Vendor Product Version Status
Adobe
Acrobat Reader

unspecified to <= 20.005.30418

Affected
Adobe
Acrobat Reader

unspecified to <= 22.003.20282

Affected
Adobe
Acrobat Reader

unspecified to <= 22.003.20281

Affected
Adobe
Acrobat Reader

unspecified to <= None

Affected

CVE References