CVE-2023-21608
published 2023-01-18CVE-2023-21608: Adobe Acrobat Reader versions 22.003.20282 (and earlier), 22.003.20281 (and earlier) and 20.005.30418 (and earlier) are affected by a Use After Free…
PriorityP184high7.8CVSS 3.1
AVLACLPRNUIRSUCHIHAH
KEVITWEXPLOITInitial access
CISA Known Exploited Vulnerabilitydue 2023-10-31
Exploited in the wild
EPSS
61.48%
99.1th percentile
Adobe Acrobat Reader versions 22.003.20282 (and earlier), 22.003.20281 (and earlier) and 20.005.30418 (and earlier) are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| adobe | acrobat | 20.001.30005 – 20.005.30418 | — |
| adobe | acrobat_dc | 15.008.20082 – 22.003.20282 | — |
| adobe | acrobat_dc | 15.008.20082 – 22.003.20281 | — |
| adobe | acrobat_reader | 20.001.30005 – 20.005.30418 | — |
| adobe | acrobat_reader | unspecified – 20.005.30418 | — |
| adobe | acrobat_reader_dc | 15.008.20082 – 22.003.20282 | — |
| adobe | acrobat_reader_dc | 15.008.20082 – 22.003.20281 | — |
Detection & IOCsextracted from sources · hover to see the quote
- →Exploitation requires a victim to open a malicious file; monitor for suspicious PDF or Adobe Acrobat file opens, especially from untrusted sources, in affected versions of Adobe Acrobat Reader ↗
- →Flag use of Adobe Acrobat Reader versions 22.003.20282 and earlier, 22.003.20281 and earlier, and 20.005.30418 and earlier as vulnerable targets for this Use-After-Free code execution vulnerability ↗
- ·This CVE is listed in CISA KEV (Known Exploited Vulnerabilities), confirming active in-the-wild exploitation; prioritize patching per vendor advisory APSB23-01 ↗
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
vulncheck7.8HIGH
cisa7.8HIGH
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
CISA
Adobe Acrobat and Reader Use-After-Free Vulnerability
cisa·2023-10-10·CVSS 7.8
CVE-2023-21608 [HIGH] CWE-416 Adobe Acrobat and Reader Use-After-Free Vulnerability
Vulnerability: Adobe Acrobat and Reader Use-After-Free Vulnerability
Affected: Adobe Acrobat and Reader
Adobe Acrobat and Reader contains a use-after-free vulnerability that allows for code execution in the context of the current user.
Required Action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
Notes: https://helpx.adobe.com/security/products/acrobat/apsb23-01.html; https://nvd.nist.gov/vuln/detail/CVE-2023-21608
Remediation Due Date: 2023-10-31
GHSA
GHSA-w7q6-mhgp-7c2h: Adobe Acrobat Reader versions 22
ghsa_unreviewed·2023-01-18
CVE-2023-21608 [HIGH] CWE-416 GHSA-w7q6-mhgp-7c2h: Adobe Acrobat Reader versions 22
Adobe Acrobat Reader versions 22.003.20282 (and earlier), 22.003.20281 (and earlier) and 20.005.30418 (and earlier) are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
VulnCheck
Adobe Acrobat and Reader Use-After-Free Vulnerability
vulncheck·2023·CVSS 7.8
CVE-2023-21608 [HIGH] CWE-416 Adobe Acrobat and Reader Use-After-Free Vulnerability
Adobe Acrobat and Reader Use-After-Free Vulnerability
Adobe Acrobat and Reader contains a use-after-free vulnerability that allows for code execution in the context of the current user.
Affected: Adobe Acrobat and Reader
Required Action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
Exploitation References: https://www.cisa.gov/sites/default/files/feeds/known_exploited_vulnerabilities.json
Exploit PoC: https://vulncheck.com/xdb/29d414efa30d; https://vulncheck.com/xdb/0717f1503e66
Remediation Due: 2023-10-31
No detection rules found.
No public exploits indexed.
2023-01-18
Published
2023-10-10
Added to CISA KEV
Exploited in the wild