ZeroHour

CVE-2023-21608

KEVmass

Actively Exploited Use-After-Free RCE in Adobe Acrobat and Reader

CISA: Adobe Acrobat and Reader Use-After-Free Vulnerability

CVSS 3.1
7.8 high
EPSS
61%p99
Published
()
KEV added
AI analysis

Adobe Acrobat and Reader contain a use-after-free memory-corruption flaw (CWE-416) that allows arbitrary code execution in the context of the current user. The bug is local and requires user interaction: a victim must open a malicious file, typically a crafted PDF delivered by email or web download, for the attacker's code to run. Affected builds are 22.003.20282 and earlier, 22.003.20281 and earlier, and 20.005.30418 and earlier, and CISA's affected list spans both Acrobat and Reader. Adobe shipped fixes in January 2023, but the flaw remained under active exploitation: CISA added it to the Known Exploited Vulnerabilities catalog on 2023-10-10 and EPSS gives it a 61.5% probability of exploitation within 30 days (99th percentile). No public proof-of-concept is known and any ransomware use is unconfirmed, but in-the-wild exploitation makes urgent patching necessary.

What to do: Update every Acrobat and Reader installation to a build later than 22.003.20282, 22.003.20281, and 20.005.30418 per Adobe's security advisory, using the built-in updater or enterprise deployment packages and prioritizing endpoints that handle untrusted PDFs; CISA's KEV required action is to apply the vendor's mitigations or discontinue use of the product. Until patched, query your software inventory for installs at or below the affected versions and remind users that opening a malicious PDF from an untrusted source can execute attacker code at their privilege level.

Affected
Adobe Acrobat DC22.003.20282 and earlier; 22.003.20281 and earlier; 20.005.30418 and earlier
Adobe Acrobat Reader DC22.003.20282 and earlier; 22.003.20281 and earlier; 20.005.30418 and earlier
Adobe Acrobat22.003.20282 and earlier; 22.003.20281 and earlier; 20.005.30418 and earlier
Adobe Acrobat Reader22.003.20282 and earlier; 22.003.20281 and earlier; 20.005.30418 and earlier
Estimated exposure
masshundreds of millions of users/installations plausibly affected (dominant desktop PDF viewer; cumulative install counts commonly cited at over a billion) — Acrobat/Reader is one of the most widely deployed desktop applications in the world, and the listed 22.x/20.x builds were the current release trains when fixes shipped in January 2023, so nearly every organization running unpatched Acrobat…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Adobe Acrobat Reader versions 22.003.20282 (and earlier), 22.003.20281 (and earlier) and 20.005.30418 (and earlier) are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

CISA Known Exploited Vulnerability
Affected
Adobe Acrobat and Reader
Required action
Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
Due date
Ransomware use
Unknown
Vendors
adobe
Products
acrobat dc, acrobat reader dc, acrobat, acrobat reader
Weakness
CWE-416
Vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

In the news