CVE-2023-44366: ZDI-CAN-21928: Adobe Acrobat Reader DC Font Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability
Adobe Acrobat Reader versions 23.006.20360 (and earlier) and 20.005.30524 (and earlier) are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for this Adobe Acrobat Reader vulnerability?
The vulnerability ID for this Adobe Acrobat Reader vulnerability is CVE-2023-44366.
What is the severity rating of CVE-2023-44366?
CVE-2023-44366 has a severity rating of 7.8 (high).
Which versions of Adobe Acrobat Reader are affected by CVE-2023-44366?
Adobe Acrobat Reader versions 23.006.20360 (and earlier) and 20.005.30524 (and earlier) are affected.
How can CVE-2023-44366 be exploited?
Exploitation of CVE-2023-44366 requires user interaction, where a victim must open a specially crafted file.
Where can I find more information about CVE-2023-44366?
More information about CVE-2023-44366 can be found at the following link: [Adobe Security Bulletin APSB23-54](https://helpx.adobe.com/security/products/acrobat/apsb23-54.htm)