First published: Wed Jan 18 2023(Updated: )
Adobe Acrobat Reader versions 22.003.20282 (and earlier), 22.003.20281 (and earlier) and 20.005.30418 (and earlier) are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Credit: psirt@adobe.com
Affected Software | Affected Version | How to fix |
---|---|---|
Adobe Acrobat | >=15.008.20082<=22.003.20282 | |
Adobe Acrobat Reader | >=15.008.20082<=22.003.20282 | |
Microsoft Windows | ||
Adobe Acrobat | >=15.008.20082<=22.003.20281 | |
Adobe Acrobat Reader | >=15.008.20082<=22.003.20281 | |
Apple iOS and macOS | ||
Adobe Acrobat Reader | >=20.001.30005<=20.005.30418 | |
Adobe Acrobat Reader | >=20.001.30005<=20.005.30418 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-21581 is classified as a critical severity vulnerability due to its potential to disclose sensitive memory.
To fix CVE-2023-21581, update Adobe Acrobat Reader to the latest version provided by Adobe.
Affected versions include Adobe Acrobat Reader versions 22.003.20282 and earlier, 22.003.20281 and earlier, and 20.005.30418 and earlier.
Yes, CVE-2023-21581 can be exploited by an attacker to bypass mitigations and disclose sensitive information.
Attackers can leverage the out-of-bounds read vulnerability in CVE-2023-21581 to manipulate memory access.