CVE-2023-44365: ZDI-CAN-21931: Adobe Acrobat Reader DC Font Parsing Uninitialized Variable Remote Code Execution Vulnerability
Published Nov 16, 2023
·Updated
Adobe Acrobat Reader versions 23.006.20360 (and earlier) and 20.005.30524 (and earlier) are affected by an Access of Uninitialized Pointer vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Affected Software
6 affected components
Adobe Acrobat DC>=15.008.20082<23.006.20380
Adobe Acrobat Reader DC>=15.008.20082<23.006.20380
Apple macOS
Microsoft Windows
Adobe Acrobat>=20.001.30005<=20.005.30539
Adobe Acrobat Reader>=20.001.30005<20.005.30539
Event History
Nov 16, 2023
CVE Published
09:52 AM
Data Sourced
09:52 AM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the vulnerability ID for the Adobe Acrobat Reader DC Font Parsing Uninitialized Variable Remote Code Execution vulnerability?
The vulnerability ID is CVE-2023-44365.
2
Which versions of Adobe Acrobat Reader are affected by the vulnerability?
Adobe Acrobat Reader versions 23.006.20360 (and earlier) and 20.005.30524 (and earlier) are affected.
3
What is the severity rating for the vulnerability?
The severity rating for the vulnerability is 7.8 (high).
4
How can the vulnerability be exploited?
Exploitation of this vulnerability requires user interaction, such as opening a specially crafted PDF file.
5
Is Apple macOS or Microsoft Windows affected by this vulnerability?
No, Apple macOS and Microsoft Windows are not affected.