CVE-2023-44323

CWE-416Use After Free4 documents4 sources
Severity
5.5MEDIUM
EPSS
0.2%
top 52.07%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedOct 30

Description

Adobe Acrobat for Edge version 118.0.2088.46 (and earlier) is affected by a Use After Free vulnerability. An unauthenticated attacker could leverage this vulnerability to achieve an application denial-of-service in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:HExploitability: 1.8 | Impact: 3.6

Affected Packages2 packages

CVEListV5adobe/acrobat_for_edge118.0.2088.46
NVDmicrosoft/edge_chromium< 118.0.2088.76

Patches

🔴Vulnerability Details

2
GHSA
GHSA-m4h3-mqpx-7mc5: Adobe Acrobat for Edge version 1182023-10-30
CVEList
PDF Jbig2 memory-corruption Vulnerability - MSFT T52023-10-30

📋Vendor Advisories

1
Microsoft
Adobe: CVE-2023-44323 Adobe PDF Remote Code Execution Vulnerability2023-10-10
CVE-2023-44323 (MEDIUM CVSS 5.5) | Adobe Acrobat for Edge version 118. | cvebase.io