CVE-2023-26395: Adobe Acrobat parsing PDF Out-of-bounds Write Arbitrary code execution
Adobe Acrobat Reader versions 23.001.20093 (and earlier) and 20.005.30441 (and earlier) are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2023-26395?
CVE-2023-26395 is considered a critical vulnerability due to its potential for arbitrary code execution.
How do I fix CVE-2023-26395?
To fix CVE-2023-26395, update Adobe Acrobat Reader to version 20.005.30442 or later, or Adobe Acrobat DC to version 23.001.20094 or later.
What versions of Adobe Acrobat are affected by CVE-2023-26395?
CVE-2023-26395 affects Adobe Acrobat Reader versions 23.001.20093 and earlier, and 20.005.30441 and earlier.
Does CVE-2023-26395 require user interaction for exploitation?
Yes, exploitation of CVE-2023-26395 requires user interaction.
What could be the consequence of exploiting CVE-2023-26395?
Exploiting CVE-2023-26395 could allow an attacker to execute arbitrary code in the context of the current user.