Adobe fixed actively exploited zero
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2023-26369 | Out-of-Bounds Write RCE in Adobe Acrobat and Reader via Malicious PDFs Adobe Acrobat and Reader contain an out-of-bounds write (CWE-787) memory-corruption vulnerability in the listed versions. The flaw is triggered by user interaction: a victim must open a malicious file (e.g., a crafted PDF) for exploitation to occur. Successful exploitation gives the attacker arbitrary code execution in the context of the current user. Anyone running affected versions of Acrobat, Acrobat DC, Acrobat Reader, or Acrobat Reader DC is exposed, and because Reader is the dominant PDF viewer, that spans effectively all unpatched desktops that open PDFs. The bug was exploited as a zero-day before being patched, was added to CISA's KEV catalog on 2023-09-14 with CISA warning of active attacks, and EPSS assigns a roughly 7% probability of exploitation in the next 30 days (94th percentile). Do: Upgrade all Acrobat and Reader installations to builds newer than 23.003.20284 and 20.005.30516/20.005.30514 per Adobe's security bulletin, as required by the CISA KEV listing (added 2023-09-14) which mandates applying vendor mitigations or discontinuing use. Until patched, caution users against opening PDFs from untrusted sources and consider blocking automatic PDF opening in browsers or email. Because the flaw was exploited as a zero-day, hunt for signs of compromise on endpoints that were running the affected versions. | 7.8 | 7% | KEV |
| masshundreds of millions of users (Acrobat/Reader is the world's dominant PDF viewer; effectively every unpatched desktop that opens PDFs) |
Full article213 words · extracted from securityaffairs.com · click to collapse
Pierluigi Paganini
September 12, 2023

Software giant Adobe is warning of a critical security vulnerability in the PDF Acrobat and Reader that is actively exploited in the wild.
Adobe Patch Tuesday security updates (APSB23-34) addressed a critical zero-day vulnerability actively exploited in the wild in attacks on Adobe Acrobat and Reader products.
The vulnerability, tracked as CVE-2023-26369, is an out-of-bounds write memory safety issue that can be exploited to execute arbitrary code on vulnerable installs.
“Adobe has released a security update for Adobe Acrobat and Reader for Windows and macOS. This update addresses a critical vulnerability. Successful exploitation could lead to arbitrary code execution .” reads the advisory,
“Adobe is aware that CVE-2023-26369 has been exploited in the wild in limited attacks targeting Adobe Acrobat and Reader.”
The vulnerability affects both Windows and macOS installations. Below is the list of affected versions:
Follow me on Twitter: @securityaffairs and Facebook and Mastodon
(SecurityAffairs – hacking, zero-day)
Text extracted automatically; images, tables and formatting may be missing. Original: https://securityaffairs.com/150733/security/adobe-zero-day-acrobat-reader.html