CVE-2023-38231: ZDI-CAN-21334: Adobe Acrobat Reader DC Font Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability
Published Aug 10, 2023
·Updated
Adobe Acrobat Reader versions 23.003.20244 (and earlier) and 20.005.30467 (and earlier) are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Affected Software
8 affected components
Adobe Acrobat DC>=15.008.20082<23.003.20269
Adobe Acrobat Reader DC>=15.008.20082<23.003.20269
Apple macOS
Microsoft Windows
Adobe Acrobat>=20.001.30005<=20.005.30516.10516
Adobe Acrobat Reader>=20.001.30005<20.005.30516.10516
Adobe Acrobat>=20.001.30005<20.005.30514.10514
Adobe Acrobat Reader>=20.001.30005<20.005.30514.10514
Event History
Aug 10, 2023
CVE Published
via MITRE·01:17 PM
Data Sourced
via MITRE·01:17 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the vulnerability ID of this issue?
The vulnerability ID of this issue is CVE-2023-38231.
2
Which versions of Adobe Acrobat Reader are affected by this vulnerability?
Adobe Acrobat Reader versions 23.003.20244 (and earlier) and 20.005.30467 (and earlier) are affected by this vulnerability.
3
What is the severity rating of CVE-2023-38231?
The severity rating of CVE-2023-38231 is high, with a CVSS score of 7.8.
4
What is the impact of this vulnerability?
This vulnerability could result in arbitrary code execution in the context of the current user.
5
Is user interaction required to exploit this vulnerability?
Yes, exploitation of this vulnerability requires user interaction.