CVE-2023-21604: Adobe Acrobat Reader Stack-based Buffer Overflow Arbitrary code execution
Adobe Acrobat Reader versions 22.003.20282 (and earlier), 22.003.20281 (and earlier) and 20.005.30418 (and earlier) are affected by a Stack-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-21604?
CVE-2023-21604 is a critical vulnerability due to its potential for arbitrary code execution.
Which versions of Adobe Acrobat Reader are affected by CVE-2023-21604?
Adobe Acrobat Reader versions 22.003.20282 and earlier, 22.003.20281 and earlier, as well as 20.005.30418 and earlier are affected.
How do I fix CVE-2023-21604?
To mitigate CVE-2023-21604, users should update Adobe Acrobat Reader to the latest version that resolves this vulnerability.
What type of vulnerability is CVE-2023-21604?
CVE-2023-21604 is a stack-based buffer overflow vulnerability.
Can CVE-2023-21604 be exploited remotely?
CVE-2023-21604 can potentially be exploited locally by an attacker who has access to the affected user's session.