⚠ Actively exploited
Added to CISA KEV on 2023-09-14. Federal agencies required to patch by 2023-10-05. Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable..
CVE-2023-26369 — Out-of-bounds Write in Adobe Acrobat
Severity
7.8HIGHNVD
EPSS
0.6%
top 31.62%
CISA KEV
KEV
Added 2023-09-14
Due 2023-10-05
Exploit
Exploited in wild
Active exploitation observed
Affected products
Timeline
PublishedSep 13
KEV addedSep 14
KEV dueOct 5
CISA Required Action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
Description
Acrobat Reader versions 23.003.20284 (and earlier), 20.005.30516 (and earlier) and 20.005.30514 (and earlier) are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
CVSS vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:HExploitability: 1.8 | Impact: 5.9
Affected Packages5 packages
🔴Vulnerability Details
4📋Vendor Advisories
1🕵️Threat Intelligence
1Bleepingcomputer
▶