CVE-2023-21581: Adobe Acrobat Reader DC Font Parsing Out-Of-Bounds Read Information Disclosure Vulnerability
Adobe Acrobat Reader versions 22.003.20282 (and earlier), 22.003.20281 (and earlier) and 20.005.30418 (and earlier) are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-21581?
CVE-2023-21581 is classified as a critical severity vulnerability due to its potential to disclose sensitive memory.
How do I fix CVE-2023-21581?
To fix CVE-2023-21581, update Adobe Acrobat Reader to the latest version provided by Adobe.
Which versions of Adobe Acrobat Reader are affected by CVE-2023-21581?
Affected versions include Adobe Acrobat Reader versions 22.003.20282 and earlier, 22.003.20281 and earlier, and 20.005.30418 and earlier.
Can CVE-2023-21581 be exploited remotely?
Yes, CVE-2023-21581 can be exploited by an attacker to bypass mitigations and disclose sensitive information.
What methods can attackers use to exploit CVE-2023-21581?
Attackers can leverage the out-of-bounds read vulnerability in CVE-2023-21581 to manipulate memory access.