First published: Wed Apr 12 2023(Updated: )
Adobe Acrobat Reader versions 23.001.20093 (and earlier) and 20.005.30441 (and earlier) are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Credit: psirt@adobe.com
Affected Software | Affected Version | How to fix |
---|---|---|
Adobe Acrobat Reader | >=20.001.3005<=20.005.30441 | |
Adobe Acrobat | >=15.008.20082<=23.001.20093 | |
Adobe Acrobat Reader | >=20.001.3005<=20.005.30441 | |
Adobe Acrobat Reader | >=15.008.20082<=23.001.20093 | |
Apple macOS | ||
Microsoft Windows |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-26397 is classified as a high-severity vulnerability that can lead to the disclosure of sensitive memory.
CVE-2023-26397 affects Adobe Acrobat Reader versions 23.001.20093 and earlier, as well as 20.005.30441 and earlier.
To fix CVE-2023-26397, users should update Adobe Acrobat Reader to the latest version that addresses this vulnerability.
Yes, CVE-2023-26397 can be exploited by attackers to bypass mitigations such as ASLR.
CVE-2023-26397 affects systems running vulnerable versions of Adobe Acrobat Reader on various platforms.