CVE-2023-38247: ZDI-CAN-21449: Adobe Acrobat Reader DC PDF File Parsing Out-Of-Bounds Read Information Disclosure Vulnerability
Adobe Acrobat Reader versions 23.003.20244 (and earlier) and 20.005.30467 (and earlier) are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Affected Software
Event History
Frequently Asked Questions
What is the CVE ID of this vulnerability?
The CVE ID of this vulnerability is CVE-2023-38247.
Which versions of Adobe Acrobat Reader are affected?
Adobe Acrobat Reader versions 23.003.20244 and earlier, and 20.005.30467 and earlier are affected.
What is the severity of CVE-2023-38247?
CVE-2023-38247 has a severity rating of medium with a score of 5.5.
What is the impact of this vulnerability?
This vulnerability could lead to the disclosure of sensitive memory and bypass mitigations such as ASLR.
Is there a fix available for this vulnerability?
Yes, Adobe has released a security update to address this vulnerability. Please refer to the provided reference link for more information.