CVE-2023-26369

CVSS 3.1 Score 7.8 of 10 (high)

Details

Published Sep 13, 2023
Updated: Sep 15, 2023
CWE ID 787

Summary

CVE-2023-26369 is a critical vulnerability affecting Adobe Acrobat Reader versions 23.003.20284 and earlier, 20.005.30516 and earlier, and 20.005.30514 and earlier. This issue constitutes an out-of-bounds write vulnerability, which means that data is written outside of the designated memory area. The consequence of this vulnerability is arbitrary code execution, enabling attackers to run malicious code with the privileges of the current user. The exploitation of this vulnerability necessitates user interaction, meaning that a victim must open a specially crafted file to be affected.

Ligh bulbPrevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.

Share

Affected Products

  • Adobe Acrobat DC
  • Adobe Acrobat Reader
  • Adobe Acrobat
  • Adobe Acrobat Reader DC

Affected Vendors

  • Adobe