CVE-2023-38233: ZDI-CAN-21337: Adobe Acrobat Reader DC Font Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability
Adobe Acrobat Reader versions 23.003.20244 (and earlier) and 20.005.30467 (and earlier) are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2023-38233?
CVE-2023-38233 is an out-of-bounds write vulnerability in Adobe Acrobat Reader versions 23.003.20244 (and earlier) and 20.005.30467 (and earlier) that could lead to arbitrary code execution.
How severe is CVE-2023-38233?
CVE-2023-38233 has a severity rating of 7.8, which is considered high.
How can CVE-2023-38233 be exploited?
CVE-2023-38233 can be exploited by an attacker through user interaction, requiring the victim to open a specially crafted file.
Which software versions are affected by CVE-2023-38233?
Adobe Acrobat Reader versions 23.003.20244 (and earlier) and 20.005.30467 (and earlier) are affected by CVE-2023-38233.
How can I mitigate the vulnerability in Adobe Acrobat Reader?
To mitigate the vulnerability in Adobe Acrobat Reader, it is recommended to update to version 23.003.20269 or later.