CVE-2023-21614: Adobe Acrobat Reader DC Font Parsing Out-Of-Bounds Read Information Disclosure Vulnerability
Adobe Acrobat Reader versions 22.003.20282 (and earlier), 22.003.20281 (and earlier) and 20.005.30418 (and earlier) are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-21614?
CVE-2023-21614 has been rated as a medium severity vulnerability due to its potential for sensitive data disclosure.
How do I fix CVE-2023-21614?
To fix CVE-2023-21614, update Adobe Acrobat Reader to the latest version available.
What versions are affected by CVE-2023-21614?
CVE-2023-21614 affects Adobe Acrobat Reader versions 22.003.20282 and earlier, as well as 20.005.30418 and earlier.
Can exploiting CVE-2023-21614 lead to data loss?
Exploiting CVE-2023-21614 may result in the disclosure of sensitive memory, which could potentially lead to data loss.
Are both Adobe Acrobat DC and Adobe Acrobat Reader affected by CVE-2023-21614?
Yes, both Adobe Acrobat DC and Adobe Acrobat Reader are affected by CVE-2023-21614.