CVE-2023-21586: Acrobat Reader | NULL Pointer Dereference (CWE-476)
Adobe Acrobat Reader versions 22.003.20282 (and earlier), 22.003.20281 (and earlier) and 20.005.30418 (and earlier) are affected by a NULL Pointer Dereference vulnerability. An unauthenticated attacker could leverage this vulnerability to achieve an application denial-of-service in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-21586?
CVE-2023-21586 has a high severity as it allows unauthenticated attackers to achieve application denial-of-service.
How do I fix CVE-2023-21586?
To fix CVE-2023-21586, update Adobe Acrobat Reader to version 22.003.20283 or later.
What versions of Adobe Acrobat Reader are affected by CVE-2023-21586?
Adobe Acrobat Reader versions 22.003.20282, 22.003.20281, and 20.005.30418 and earlier are affected by CVE-2023-21586.
Can CVE-2023-21586 be exploited remotely?
Yes, CVE-2023-21586 can be exploited remotely by unauthenticated attackers.
What kind of vulnerability is CVE-2023-21586?
CVE-2023-21586 is a NULL Pointer Dereference vulnerability.