CVE-2023-26369
published 2023-09-13CVE-2023-26369: Acrobat Reader versions 23.003.20284 (and earlier), 20.005.30516 (and earlier) and 20.005.30514 (and earlier) are affected by an out-of-bounds write…
PriorityP183high7.8CVSS 3.1
AVLACLPRNUIRSUCHIHAH
KEVITW
CISA Known Exploited Vulnerabilitydue 2023-10-05
Exploited in the wild
EPSS
7.04%
93.5th percentile
Acrobat Reader versions 23.003.20284 (and earlier), 20.005.30516 (and earlier) and 20.005.30514 (and earlier) are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Affected
5 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| adobe | acrobat | >= 20.001.3005 < 20.005.30524 | 20.005.30524 |
| adobe | acrobat_dc | >= 15.007.20033 < 23.006.20320 | 23.006.20320 |
| adobe | acrobat_reader | <= 20.005.30514 | — |
| adobe | acrobat_reader | >= 20.001.3005 < 20.005.30524 | 20.005.30524 |
| adobe | acrobat_reader_dc | >= 15.007.20033 < 23.006.20320 | 23.006.20320 |
Detection & IOCsextracted from sources · hover to see the quote
- →Check Point IPS signature available for detection: 'Adobe Acrobat and Reader Out-of-bounds Write (APSB23-34: CVE-2023-26369)' ↗
- →Exploitation requires a victim to open a specially crafted (malicious) PDF document — monitor for suspicious PDF opens in Adobe Acrobat/Reader processes leading to unexpected child process spawning or memory writes. ↗
- →Exploitation requires user interaction; the attack vector is a malicious file (PDF). Alert on Adobe Acrobat/Reader versions at or below 23.003.20284 (Win/Mac), 23.003.20244 (Win), 20.005.30516 (Mac), 20.005.30514 (Win) opening externally sourced PDFs. ↗
- →CISA KEV listing confirms active exploitation in the wild — prioritize detection on all Adobe Acrobat and Reader deployments. ↗
- ·All four Acrobat/Reader product tracks are affected; ensure version checks cover both Windows and macOS builds as version numbers differ by platform. ↗
- ·CISA mandated remediation deadline was 2023-10-05; any unpatched asset past this date should be treated as high-priority risk. ↗
CVSS provenance
nvdv3.17.8HIGHCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
vulncheck7.8HIGH
cisa7.8HIGH
CVEs like this are exactly what “Exploited This Week” covers.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-pxpg-54ph-g5gh: Acrobat Reader versions 23
ghsa_unreviewed·2023-09-13
CVE-2023-26369 [HIGH] CWE-787 GHSA-pxpg-54ph-g5gh: Acrobat Reader versions 23
Acrobat Reader versions 23.003.20284 (and earlier), 20.005.30516 (and earlier) and 20.005.30514 (and earlier) are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
VulnCheck
Adobe Acrobat and Reader Out-of-Bounds Write Vulnerability
vulncheck·2023·CVSS 7.8
CVE-2023-26369 [HIGH] CWE-787 Adobe Acrobat and Reader Out-of-Bounds Write Vulnerability
Adobe Acrobat and Reader Out-of-Bounds Write Vulnerability
Adobe Acrobat and Reader contains an out-of-bounds write vulnerability that allows for code execution.
Affected: Adobe Acrobat and Reader
Required Action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
Exploitation References: https://docs.google.com/spreadsheets/d/1lkNJ0uQwbeC1ZTRrxdtuPLCIl7mlUreoKfSIgajnSyY/edit; https://helpx.adobe.com/security/products/acrobat/apsb23-34.html; https://www.cve.org/CVERecord?id=CVE-2023-26369; https://www.cisa.gov/sites/default/files/feeds/known_exploited_vulnerabilities.json; https://googleprojectzero.github.io/0days-in-the-wild/0day-RCAs/2023/CVE-2023-26369.html; https://ti.qianxin.com/uploads/2024/02/02/dcc93e586f9028c68e7ab34c332
Project0
Project Zero RCA: CVE-2023-26369: Adobe Acrobat PDF Reader RCE when processing TTF fonts
project_zero·CVSS 7.8
CVE-2023-26369 [HIGH] Project Zero RCA: CVE-2023-26369: Adobe Acrobat PDF Reader RCE when processing TTF fonts
# CVE-2023-26369: Adobe Acrobat PDF Reader RCE when processing TTF fonts
Clement Lecigne, Google Threat Analysis Group
## The Basics
**Disclosure or Patch Date:** September, 12, 2023
**Product:** Adobe Acrobat Reader on Windows and MacOS
**Advisory:** https://helpx.adobe.com/security/products/acrobat/apsb23-34.html
**Affected Versions:** 23.003.20284 and earlier versions
**First Patched Version:** 23.006.20320
**Issue/Bug Report:** N/A
**Patch CL:** N/A (closed source)
**Bug-Introducing CL:** N/A
**Reporter(s):** Anonymous
## The Code
**Proof-of-concept:**
TTF font with the following bitmap tables.
```
EBLC :
version : 0x20000
numSizes : 0x1
[-] 0th bitmapSizeTable
indexSubTableArrayOffset : 0x38
indexTablesSize : 0x100
numberOfIndexSubTables : 0x2
colorRef : 0x0
hori : 0b f
CISA
Adobe Acrobat and Reader Out-of-Bounds Write Vulnerability
cisa·2023-09-14·CVSS 7.8
CVE-2023-26369 [HIGH] CWE-787 Adobe Acrobat and Reader Out-of-Bounds Write Vulnerability
Vulnerability: Adobe Acrobat and Reader Out-of-Bounds Write Vulnerability
Affected: Adobe Acrobat and Reader
Adobe Acrobat and Reader contains an out-of-bounds write vulnerability that allows for code execution.
Required Action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
Notes: https://helpx.adobe.com/security/products/acrobat/apsb23-34.html; https://nvd.nist.gov/vuln/detail/CVE-2023-26369
Remediation Due Date: 2023-10-05
No detection rules found.
No public exploits indexed.
Checkpoint
18th September – Threat Intelligence Report
blogs_checkpoint·2023-09-18
CVE-2023-26369 18th September – Threat Intelligence Report
Latest Publications
CPR Podcast Channel
AI Research
Web 3.0 Security
Intelligence Reports
ThreatCloud AI
Threat Intelligence & Research
Zero Day Protection
Sandblast File Analysis
About Us
SUBSCRIBE
2026
2025
2024
2023
2022
2021
2020
2019
2018
2017
2016
## 18th September – Threat Intelligence Report
For the latest discoveries in cyber research for the week of 11th September, please download our Threat_Intelligence Bulletin .
TOP ATTACKS AND BREACHES
The American resort, casino and hotel chain MGM has suffered a cyber-attack that resulted in widespread disruption across the company’s hotels and casinos, and has shut down its internal networks as a precaution. The cyber-attack paralyzed the company’s ATMs, slot machines, room digital key cards and electronic paymen
Krebs
Adobe, Apple, Google & Microsoft Patch 0-Day Bugs
blogs_krebs·2023-09-12·CVSS 6.5
[MEDIUM] Adobe, Apple, Google & Microsoft Patch 0-Day Bugs
Microsoft today issued software updates to fix at least five dozen security holes in Windows and supported software, including patches for two zero-day vulnerabilities that are already being exploited. Also, Adobe , Google Chrome and Apple iOS users may have their own zero-day patching to do.
On Sept. 7, researchers at Citizen Lab warned they were seeing active exploitation of a “zero-click,” zero-day flaw to install spyware on iOS devices without any interaction from the victim.
“The exploit chain was capable of compromising iPhones running the latest version of iOS (16.6) without any interaction from the victim,” the researchers wrote.
According to Citizen Lab, the exploit uses malicious images sent via iMessage , an embedded component of Apple’s iOS that has been the source of previo
Bleepingcomputer
Adobe warns of critical Acrobat and Reader zero-day exploited in attacks
blogs_bleepingcomputer·2023-09-12·CVSS 7.8
CVE-2023-26369 [HIGH] Adobe warns of critical Acrobat and Reader zero-day exploited in attacks
## Adobe warns of critical Acrobat and Reader zero-day exploited in attacks
## Sergiu Gatlan
Adobe has released security updates to patch a zero-day vulnerability in Acrobat and Reader tagged as exploited in attacks.
Even though additional information on the attacks is yet to be disclosed, the zero-day is known to affect both Windows and macOS systems.
"Adobe is aware that CVE-2023-26369 has been exploited in the wild in limited attacks targeting Adobe Acrobat and Reader," the company said in a security advisory published today.
The critical security flaw is tracked as CVE-2023-26369 and can let attackers gain code execution after successfully exploiting an out-of-bounds write weakness .
While threat actors can exploit it in low-complexity attacks without requiring privileges, the fl
Qualys
Microsoft and Adobe Patch Tuesday, September 2023 Security Update Review
blogs_qualys·2023-09-12
Microsoft and Adobe Patch Tuesday, September 2023 Security Update Review
## Table of Contents
Microsoft Patch Tuesday for September 2023
Adobe Patches for September 2023
Zero-day Vulnerability Patched in September Patch Tuesday Edition
Other Critical Severity Vulnerabilities Patched in September Patch Tuesday Edition
Other Microsoft Vulnerability Highlights
Microsoft Release Summary
Discover and Prioritize Vulnerabilities in Vulnerability Management, Detection & Response (VMDR)
Rapid Response with Patch Management (PM)
EVALUATE Vendor-Suggested Mitigation with Policy Compliance (PC)
EXECUTE Mitigation Using Qualys Custom Assessment and Remediation (CAR)
Qualys Monthly Webinar Series
Microsoft has released the Patch Tuesday edition for September. This month’s updates have addressed 66 security vulnerabilities (including Edge Chromium-based) in multip
Krebs
Adobe, Apple, Google & Microsoft Patch 0-Day Bugs
blogs_krebs·2023-09-12·CVSS 6.5
[MEDIUM] Adobe, Apple, Google & Microsoft Patch 0-Day Bugs
Microsoft today issued software updates to fix at least five dozen security holes in Windows and supported software, including patches for two zero-day vulnerabilities that are already being exploited. Also, Adobe, Google Chrome and Apple iOS users may have their own zero-day patching to do.
On Sept. 7, researchers at Citizen Lab warned they were seeing active exploitation of a “zero-click,” zero-day flaw to install spyware on iOS devices without any interaction from the victim.
“The exploit chain was capable of compromising iPhones running the latest version of iOS (16.6) without any interaction from the victim,” the researchers wrote.
According to Citizen Lab, the exploit uses malicious images sent via iMessage, an embedded component of Apple’s iOS that has been the source of previous
Qualys
Microsoft and Adobe Patch Tuesday, September 2023 Security Update Review | Qualys
blogs_qualys·2023-09-12
Microsoft and Adobe Patch Tuesday, September 2023 Security Update Review | Qualys
#### Table of Contents
- Microsoft Patch Tuesday for September 2023
- Adobe Patches for September 2023
- Zero-day Vulnerability Patched in September Patch Tuesday Edition
- Other Critical Severity Vulnerabilities Patched in September Patch Tuesday Edition
- Other Microsoft Vulnerability Highlights
- Microsoft Release Summary
- Discover and Prioritize Vulnerabilities in Vulnerability Management, Detection & Response (VMDR)
- Rapid Response with Patch Management (PM)
- EVALUATE Vendor-Suggested Mitigation with Policy Compliance (PC)
- EXECUTE Mitigation Using Qualys Custom Assessment and Remediation (CAR)
- Qualys Monthly Webinar Series
Microsoft has released the Patch Tuesday edition for September. This month’s updates have addressed 66 security vulnerabilities (including Edge Chromium-ba
Zscaler
Zscaler found Adobe security vulnerabilities | 09-12-2023
blogs_zscaler
Zscaler found Adobe security vulnerabilities | 09-12-2023
Provide users with seamless, secure, reliable access to applications and data.
Build and run secure cloud apps, enable zero trust cloud connectivity, and protect workloads from data center to cloud.
Provide zero trust connectivity for IoT and OT devices and secure remote access to OT systems.
Provide zero trust site-to-site connectivity and reliable access to B2B apps for partners.
Industry Report
Zscaler: A Leader in the 2025 Gartner® Magic Quadrant™ for Security Service Edge (SSE)
USE CASES
INDUSTRY & MARKET SOLUTIONS
PARTNERS
TECHNOLOGY PARTNERS
Resource Center
Events & Trainings
Security Research & Services
Tools
Community & Support
CXO REVOLUTIONARIES
Amplifying the voices of real-world digital and zero trust pioneers
Discover how it began and where it’s going
Meet o
2023-09-13
Published
2023-09-14
Added to CISA KEV
Exploited in the wild