ZeroHour
Security Affairspublished ()ingested @securityaffairs

Adobe fixed actively exploited zero

criticalExploit / PoC exploited in the wildimportance 60CVE-2023-26369

Vulnerabilities mentionedAll →

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2023-26369
Out-of-Bounds Write RCE in Adobe Acrobat and Reader via Malicious PDFs

Adobe Acrobat and Reader contain an out-of-bounds write (CWE-787) memory-corruption vulnerability in the listed versions. The flaw is triggered by user interaction: a victim must open a malicious file (e.g., a crafted PDF) for exploitation to occur. Successful exploitation gives the attacker arbitrary code execution in the context of the current user. Anyone running affected versions of Acrobat, Acrobat DC, Acrobat Reader, or Acrobat Reader DC is exposed, and because Reader is the dominant PDF viewer, that spans effectively all unpatched desktops that open PDFs. The bug was exploited as a zero-day before being patched, was added to CISA's KEV catalog on 2023-09-14 with CISA warning of active attacks, and EPSS assigns a roughly 7% probability of exploitation in the next 30 days (94th percentile).

Do: Upgrade all Acrobat and Reader installations to builds newer than 23.003.20284 and 20.005.30516/20.005.30514 per Adobe's security bulletin, as required by the CISA KEV listing (added 2023-09-14) which mandates applying vendor mitigations or discontinuing use. Until patched, caution users against opening PDFs from untrusted sources and consider blocking automatic PDF opening in browsers or email. Because the flaw was exploited as a zero-day, hunt for signs of compromise on endpoints that were running the affected versions.

7.87% KEV
  • Adobe Acrobat / Acrobat DC / Acrobat Reader / Acrobat Reader DC 23.003.20284 and earlier
  • Adobe Acrobat / Acrobat Reader 20.005.30516 and earlier
  • Adobe Acrobat / Acrobat Reader 20.005.30514 and earlier
masshundreds of millions of users (Acrobat/Reader is the world's dominant PDF viewer; effectively every unpatched desktop that opens PDFs)
Full article213 words · extracted from securityaffairs.com · click to collapse

Pierluigi Paganini September 12, 2023

Software giant Adobe is warning of a critical security vulnerability in the PDF Acrobat and Reader that is actively exploited in the wild.

Adobe Patch Tuesday security updates (APSB23-34) addressed a critical zero-day vulnerability actively exploited in the wild in attacks on Adobe Acrobat and Reader products.

The vulnerability, tracked as CVE-2023-26369, is an out-of-bounds write memory safety issue that can be exploited to execute arbitrary code on vulnerable installs.

“Adobe has released a security update for Adobe Acrobat and Reader for Windows and macOS. This update addresses a critical vulnerability. Successful exploitation could lead to arbitrary code execution .” reads the advisory

“Adobe is aware that CVE-2023-26369 has been exploited in the wild in limited attacks targeting Adobe Acrobat and Reader.”

The vulnerability affects both Windows and macOS installations. Below is the list of affected versions:

ProductTrackAffected VersionsPlatform
Acrobat DC Continuous 
23.003.20284 and earlier versionsWindows &  macOS
Acrobat Reader DCContinuous 23.003.20284 and earlier versions
 
Windows & macOS


     
Acrobat 2020Classic 2020           20.005.30516 (Mac) 20.005.30514 (Win)and earlier versions
 
Windows & macOS
Acrobat Reader 2020Classic 2020           20.005.30516 (Mac)20.005.30514 (Win)and earlier versionsWindows & macOS

Follow me on Twitter: @securityaffairs and Facebook and Mastodon

Pierluigi Paganini

(SecurityAffairs – hacking, zero-day)



Text extracted automatically; images, tables and formatting may be missing. Original: https://securityaffairs.com/150733/security/adobe-zero-day-acrobat-reader.html