CVE-2023-26369: [Google Project Zero] Adobe Acrobat DC OOBW 0-day actively exploited in the wild
Acrobat Reader versions 23.003.20284 (and earlier), 20.005.30516 (and earlier) and 20.005.30514 (and earlier) are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Other sources
Adobe Acrobat and Reader contains an out-of-bounds write vulnerability that allows for code execution.
— CISA
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Compensating control
Discontinue use of Adobe Acrobat Reader Notification Manager if running versions 23.003.20284 (and earlier), 20.005.30516 (and earlier), or 20.005.30514 (and earlier) when vendor mitigations are unavailable.
Event History
Frequently Asked Questions
What is the vulnerability ID for this Adobe Acrobat and Reader out-of-bounds write vulnerability?
The vulnerability ID for this Adobe Acrobat and Reader out-of-bounds write vulnerability is CVE-2023-26369.
Which versions of Adobe Acrobat and Reader are affected by this vulnerability?
The versions affected by this vulnerability are Acrobat Reader versions 23.003.20284 (and earlier), 20.005.30516 (and earlier), and 20.005.30514 (and earlier).
What is the severity of CVE-2023-26369?
The severity of CVE-2023-26369 is high with a CVSS score of 7.8.
How can this vulnerability be exploited?
Exploitation of this vulnerability requires user interaction.
Where can I find more information about this vulnerability?
More information about this vulnerability can be found at the following link: https://helpx.adobe.com/security/products/acrobat/apsb23-34.html