CVE-2023-29303
published 2023-08-10CVE-2023-29303: Adobe Acrobat Reader versions 23.003.20244 (and earlier) and 20.005.30467 (and earlier) are affected by a Use After Free vulnerability that could lead to…
PriorityP429medium5.5CVSS 3.1
AVLACLPRNUIRSUCHINAN
EPSS
2.94%
85.7th percentile
Adobe Acrobat Reader versions 23.003.20244 (and earlier) and 20.005.30467 (and earlier) are affected by a Use After Free vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Affected
7 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| adobe | acrobat | >= 20.001.30005 < 20.005.30514.10514 | 20.005.30514.10514 |
| adobe | acrobat | 20.001.30005 – 20.005.30516.10516 | — |
| adobe | acrobat_dc | >= 15.008.20082 < 23.003.20269 | 23.003.20269 |
| adobe | acrobat_reader | <= 23.003.20244 | — |
| adobe | acrobat_reader | >= 20.001.30005 < 20.005.30516.10516 | 20.005.30516.10516 |
| adobe | acrobat_reader | >= 20.001.30005 < 20.005.30514.10514 | 20.005.30514.10514 |
| adobe | acrobat_reader_dc | >= 15.008.20082 < 23.003.20269 | 23.003.20269 |
CVSS provenance
nvdv3.15.5MEDIUMCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
cisa9.8CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-w2m3-743c-qwm5: Adobe Acrobat Reader versions 23
ghsa_unreviewed·2023-08-10
CVE-2023-29303 [MEDIUM] CWE-416 GHSA-w2m3-743c-qwm5: Adobe Acrobat Reader versions 23
Adobe Acrobat Reader versions 23.003.20244 (and earlier) and 20.005.30467 (and earlier) are affected by a Use After Free vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
CISA
SolarView Compact Command Injection Vulnerability
cisa·2023-07-13·CVSS 9.8
CVE-2022-29303 [CRITICAL] CWE-78 SolarView Compact Command Injection Vulnerability
Vulnerability: SolarView Compact Command Injection Vulnerability
Affected: SolarView Compact
SolarView Compact contains a command injection vulnerability due to improper validation of input values on the send test mail console of the product's web server.
Required Action: Apply updates per vendor instructions or discontinue use of the product if updates are unavailable.
Notes: https://jvn.jp/en/vu/JVNVU92327282/; https://nvd.nist.gov/vuln/detail/CVE-2022-29303
Remediation Due Date: 2023-08-03
No detection rules found.
No public exploits indexed.
2023-08-10
Published