Update Adobe Acrobat and Reader to Patch Actively Exploited Vulnerability
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2023-26369 | Out-of-Bounds Write RCE in Adobe Acrobat and Reader via Malicious PDFs Adobe Acrobat and Reader contain an out-of-bounds write (CWE-787) memory-corruption vulnerability in the listed versions. The flaw is triggered by user interaction: a victim must open a malicious file (e.g., a crafted PDF) for exploitation to occur. Successful exploitation gives the attacker arbitrary code execution in the context of the current user. Anyone running affected versions of Acrobat, Acrobat DC, Acrobat Reader, or Acrobat Reader DC is exposed, and because Reader is the dominant PDF viewer, that spans effectively all unpatched desktops that open PDFs. The bug was exploited as a zero-day before being patched, was added to CISA's KEV catalog on 2023-09-14 with CISA warning of active attacks, and EPSS assigns a roughly 7% probability of exploitation in the next 30 days (94th percentile). Do: Upgrade all Acrobat and Reader installations to builds newer than 23.003.20284 and 20.005.30516/20.005.30514 per Adobe's security bulletin, as required by the CISA KEV listing (added 2023-09-14) which mandates applying vendor mitigations or discontinuing use. Until patched, caution users against opening PDFs from untrusted sources and consider blocking automatic PDF opening in browsers or email. Because the flaw was exploited as a zero-day, hunt for signs of compromise on endpoints that were running the affected versions. | 7.8 | 7% | KEV |
| masshundreds of millions of users (Acrobat/Reader is the world's dominant PDF viewer; effectively every unpatched desktop that opens PDFs) | |
| CVE-2023-29305 +1 in the same advisory: …29306 | Adobe Connect versions 12.3 and earlier are affected by a reflected Cross-Site Scripting (XSS) vulnerability. Adobe Connect versions 12.3 and earlier are affected by a reflected Cross-Site Scripting (XSS) vulnerability. If an attacker is able to convince a victim to visit a URL referencing a vulnerable page, malicious JavaScript content may be executed within the context of the victim's browser. NVD description · AI analysis pending | 6.1 | <1% |
| — | ||
| CVE-2023-38214 +1 in the same advisory: …38215 | Adobe Experience Manager versions 6.5.17 and earlier are affected by a reflected Cross-Site Scripting (XSS) vulnerability. Adobe Experience Manager versions 6.5.17 and earlier are affected by a reflected Cross-Site Scripting (XSS) vulnerability. If a low-privileged attacker is able to convince a victim to visit a URL referencing a vulnerable page, malicious JavaScript content may be executed within the context of the victim's browser. NVD description · AI analysis pending | 5.4 | <1% |
| — |
Full article260 words · extracted from thehackernews.com · click to collapse
Ravie LakshmananSep 13, 2023Vulnerability / Zero Day
Adobe's Patch Tuesday update for September 2023 comes with a patch for a critical actively exploited security flaw in Acrobat and Reader that could permit an attacker to execute malicious code on susceptible systems.
The vulnerability, tracked as CVE-2023-26369, is rated 7.8 for severity on the CVSS scoring system and impacts both Windows and macOS versions of Acrobat DC, Acrobat Reader DC, Acrobat 2020, and Acrobat Reader 2020.
Described as an out-of-bounds write, successful exploitation of the bug could lead to code execution by opening a specially crafted PDF document. Adobe did not disclose any additional details about the issue or the targeting involved.
"Adobe is aware that CVE-2023-26369 has been exploited in the wild in limited attacks targeting Adobe Acrobat and Reader," the company acknowledged in an advisory.
CVE-2023-26369 affects the below versions -
- Acrobat DC (23.003.20284 and earlier versions) - Fixed in 23.006.20320
- Acrobat Reader DC (23.003.20284 and earlier versions) - Fixed in 23.006.20320
- Acrobat 2020 (20.005.30514 for Windows and earlier versions, 20.005.30516 for macOS and earlier versions) - Fixed in 20.005.30524
- Acrobat Reader 2020 (20.005.30514 for Windows and earlier versions, 20.005.30516 for macOS and earlier versions) - Fixed in 20.005.30524
Also patched by the software maker are two cross-site scripting flaws each in Adobe Connect (CVE-2023-29305 and CVE-2023-29306) and Adobe Experience Manager (CVE-2023-38214 and CVE-2023-38215) that could lead to arbitrary code execution.
Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post.
Text extracted automatically; images, tables and formatting may be missing. Original: https://thehackernews.com/2023/09/update-adobe-acrobat-and-reader-to.html