CVE-2023-44361: ZDI-CAN-22041: Adobe Acrobat Reader DC AcroForm Doc Object Use-After-Free Information Disclosure Vulnerability
Adobe Acrobat Reader versions 23.006.20360 (and earlier) and 20.005.30524 (and earlier) are affected by a Use After Free vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2023-44361?
CVE-2023-44361 is a Use After Free vulnerability in Adobe Acrobat Reader DC that could lead to disclosure of sensitive memory.
How can an attacker exploit CVE-2023-44361?
An attacker could leverage CVE-2023-44361 to bypass mitigations such as ASLR.
Which versions of Adobe Acrobat Reader DC are affected by CVE-2023-44361?
Adobe Acrobat Reader versions 23.006.20360 and earlier are affected by CVE-2023-44361.
How severe is CVE-2023-44361?
CVE-2023-44361 has a severity score of 5.5 which is considered medium.
Where can I find more information about CVE-2023-44361?
You can find more information about CVE-2023-44361 at the following link: [Adobe Security Bulletin APSB23-54](https://helpx.adobe.com/security/products/acrobat/apsb23-54.htm)