⚠ Actively exploited
Added to CISA KEV on 2023-09-14. Federal agencies required to patch by 2023-10-05. Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable..

CVE-2023-26369Out-of-bounds Write in Adobe Acrobat

Severity
7.8HIGHNVD
EPSS
0.6%
top 31.62%
CISA KEV
KEV
Added 2023-09-14
Due 2023-10-05
Exploit
Exploited in wild
Active exploitation observed
Timeline
PublishedSep 13
KEV addedSep 14
KEV dueOct 5
CISA Required Action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

Description

Acrobat Reader versions 23.003.20284 (and earlier), 20.005.30516 (and earlier) and 20.005.30514 (and earlier) are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:HExploitability: 1.8 | Impact: 5.9

Affected Packages5 packages

NVDadobe/acrobat_reader20.001.300520.005.30524
NVDadobe/acrobat_reader_dc15.007.2003323.006.20320
CVEListV5adobe/acrobat_reader20.005.30514
NVDadobe/acrobat20.001.300520.005.30524
NVDadobe/acrobat_dc15.007.2003323.006.20320

🔴Vulnerability Details

4
CVEList
[Google Project Zero] Adobe Acrobat DC OOBW 0-day actively exploited in the wild2023-09-13
GHSA
GHSA-pxpg-54ph-g5gh: Acrobat Reader versions 232023-09-13
VulnCheck
Adobe Acrobat and Reader Out-of-Bounds Write Vulnerability2023
Project0
Project Zero RCA: CVE-2023-26369: Adobe Acrobat PDF Reader RCE when processing TTF fonts

📋Vendor Advisories

1
CISA
Adobe Acrobat and Reader Out-of-Bounds Write Vulnerability2023-09-14

🕵️Threat Intelligence

1
Bleepingcomputer
Adobe warns of critical Acrobat and Reader zero-day exploited in attacks2023-09-12
CVE-2023-26369 — Out-of-bounds Write in Adobe Acrobat | cvebase