CVE-2023-21583: Adobe Bridge Font Parsing Out-Of-Bounds Read Information Disclosure Vulnerability
Adobe Bridge versions 12.0.3 (and earlier) and 13.0.1 (and earlier) are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2023-21583?
CVE-2023-21583 is an out-of-bounds read vulnerability affecting Adobe Bridge versions 12.0.3 (and earlier) and 13.0.1 (and earlier).
How severe is CVE-2023-21583?
CVE-2023-21583 has a severity score of 5.5, which is considered medium.
What software versions are affected by CVE-2023-21583?
Adobe Bridge versions 12.0.3 (and earlier) and 13.0.1 (and earlier) are affected by CVE-2023-21583.
What is the impact of CVE-2023-21583?
CVE-2023-21583 could lead to the disclosure of sensitive memory and bypassing of mitigations such as ASLR.
Is Apple macOS or Microsoft Windows vulnerable to CVE-2023-21583?
No, Apple macOS and Microsoft Windows are not vulnerable to CVE-2023-21583.
How can I find more information about CVE-2023-21583?
You can find more information about CVE-2023-21583 on the Adobe security bulletin at https://helpx.adobe.com/security/products/bridge/apsb23-09.html.