CISA Warns of Actively Exploited Adobe Acrobat Reader Vulnerability
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2023-21608 | Actively Exploited Use-After-Free RCE in Adobe Acrobat and Reader Adobe Acrobat and Reader contain a use-after-free memory-corruption flaw (CWE-416) that allows arbitrary code execution in the context of the current user. The bug is local and requires user interaction: a victim must open a malicious file, typically a crafted PDF delivered by email or web download, for the attacker's code to run. Affected builds are 22.003.20282 and earlier, 22.003.20281 and earlier, and 20.005.30418 and earlier, and CISA's affected list spans both Acrobat and Reader. Adobe shipped fixes in January 2023, but the flaw remained under active exploitation: CISA added it to the Known Exploited Vulnerabilities catalog on 2023-10-10 and EPSS gives it a 61.5% probability of exploitation within 30 days (99th percentile). No public proof-of-concept is known and any ransomware use is unconfirmed, but in-the-wild exploitation makes urgent patching necessary. Do: Update every Acrobat and Reader installation to a build later than 22.003.20282, 22.003.20281, and 20.005.30418 per Adobe's security advisory, using the built-in updater or enterprise deployment packages and prioritizing endpoints that handle untrusted PDFs; CISA's KEV required action is to apply the vendor's mitigations or discontinue use of the product. Until patched, query your software inventory for installs at or below the affected versions and remind users that opening a malicious PDF from an untrusted source can execute attacker code at their privilege level. | 7.8 | 61% | KEV |
| masshundreds of millions of users/installations plausibly affected (dominant desktop PDF viewer; cumulative install counts commonly cited at over a billion) | |
| CVE-2023-26369 | Out-of-Bounds Write RCE in Adobe Acrobat and Reader via Malicious PDFs Adobe Acrobat and Reader contain an out-of-bounds write (CWE-787) memory-corruption vulnerability in the listed versions. The flaw is triggered by user interaction: a victim must open a malicious file (e.g., a crafted PDF) for exploitation to occur. Successful exploitation gives the attacker arbitrary code execution in the context of the current user. Anyone running affected versions of Acrobat, Acrobat DC, Acrobat Reader, or Acrobat Reader DC is exposed, and because Reader is the dominant PDF viewer, that spans effectively all unpatched desktops that open PDFs. The bug was exploited as a zero-day before being patched, was added to CISA's KEV catalog on 2023-09-14 with CISA warning of active attacks, and EPSS assigns a roughly 7% probability of exploitation in the next 30 days (94th percentile). Do: Upgrade all Acrobat and Reader installations to builds newer than 23.003.20284 and 20.005.30516/20.005.30514 per Adobe's security bulletin, as required by the CISA KEV listing (added 2023-09-14) which mandates applying vendor mitigations or discontinuing use. Until patched, caution users against opening PDFs from untrusted sources and consider blocking automatic PDF opening in browsers or email. Because the flaw was exploited as a zero-day, hunt for signs of compromise on endpoints that were running the affected versions. | 7.8 | 7% | KEV |
| masshundreds of millions of users (Acrobat/Reader is the world's dominant PDF viewer; effectively every unpatched desktop that opens PDFs) |
Full article273 words · extracted from thehackernews.com · click to collapse
Ravie LakshmananOct 11, 2023Vulnerability / Exploit
The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Tuesday added a high-severity flaw in Adobe Acrobat Reader to its Known Exploited Vulnerabilities (KEV) catalog, citing evidence of active exploitation.
Tracked as CVE-2023-21608 (CVSS score: 7.8), the vulnerability has been described as a use-after-free bug that can be exploited to achieve remote code execution (RCE) with the privileges of the current user.
A patch for the flaw was released by Adobe in January 2023. HackSys security researchers Ashfaq Ansari and Krishnakant Patil were credited with discovering and reporting the flaw.
The following versions of the software are impacted -
- Acrobat DC - 22.003.20282 (Win), 22.003.20281 (Mac) and earlier versions (fixed in 22.003.20310)
- Acrobat Reader DC - 22.003.20282 (Win), 22.003.20281 (Mac) and earlier versions (fixed in 22.003.20310)
- Acrobat 2020 - 20.005.30418 and earlier versions (fixed in 20.005.30436)
- Acrobat Reader 2020 - 20.005.30418 and earlier versions (fixed in 20.005.30436)
Details surrounding the nature of the exploitation and the threat actors that may be abusing CVE-2023-21608 are currently unknown. A proof-of-concept (PoC) exploit for the flaw was made available in late January 2023.
CVE-2023-21608 is also the second Adobe Acrobat and Reader vulnerability that has seen in-the-wild exploitation this year after CVE-2023-26369, an out-of-bounds write issue that could result in code execution by opening a specially crafted PDF document.
Federal Civilian Executive Branch (FCEB) agencies are required to apply the vendor-provided patches by October 31, 2023, to secure their networks against potential threats.
Found this article interesting? Follow us on Google News, Twitter and LinkedIn to read more exclusive content we post.
Text extracted automatically; images, tables and formatting may be missing. Original: https://thehackernews.com/2023/10/us-cybersecurity-agency-warns-of.html