CVE-2023-21608
KEVmassActively Exploited Use-After-Free RCE in Adobe Acrobat and Reader
CISA: Adobe Acrobat and Reader Use-After-Free Vulnerability
Adobe Acrobat and Reader contain a use-after-free memory-corruption flaw (CWE-416) that allows arbitrary code execution in the context of the current user. The bug is local and requires user interaction: a victim must open a malicious file, typically a crafted PDF delivered by email or web download, for the attacker's code to run. Affected builds are 22.003.20282 and earlier, 22.003.20281 and earlier, and 20.005.30418 and earlier, and CISA's affected list spans both Acrobat and Reader. Adobe shipped fixes in January 2023, but the flaw remained under active exploitation: CISA added it to the Known Exploited Vulnerabilities catalog on 2023-10-10 and EPSS gives it a 61.5% probability of exploitation within 30 days (99th percentile). No public proof-of-concept is known and any ransomware use is unconfirmed, but in-the-wild exploitation makes urgent patching necessary.
What to do: Update every Acrobat and Reader installation to a build later than 22.003.20282, 22.003.20281, and 20.005.30418 per Adobe's security advisory, using the built-in updater or enterprise deployment packages and prioritizing endpoints that handle untrusted PDFs; CISA's KEV required action is to apply the vendor's mitigations or discontinue use of the product. Until patched, query your software inventory for installs at or below the affected versions and remind users that opening a malicious PDF from an untrusted source can execute attacker code at their privilege level.
| Adobe Acrobat DC | 22.003.20282 and earlier; 22.003.20281 and earlier; 20.005.30418 and earlier |
| Adobe Acrobat Reader DC | 22.003.20282 and earlier; 22.003.20281 and earlier; 20.005.30418 and earlier |
| Adobe Acrobat | 22.003.20282 and earlier; 22.003.20281 and earlier; 20.005.30418 and earlier |
| Adobe Acrobat Reader | 22.003.20282 and earlier; 22.003.20281 and earlier; 20.005.30418 and earlier |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Adobe Acrobat Reader versions 22.003.20282 (and earlier), 22.003.20281 (and earlier) and 20.005.30418 (and earlier) are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
- Affected
- Adobe Acrobat and Reader
- Required action
- Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
- Due date
- Ransomware use
- Unknown
- Vendors
- adobe
- Products
- acrobat dc, acrobat reader dc, acrobat, acrobat reader
- Weakness
- CWE-416
- Vector
- CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H