CVE-2023-21608

Confirmed PUBLISHED

Adobe Acrobat Reader DC resetForm Use-After-Free Remote Code Execution Vulnerability

Adobe · Acrobat Reader
Exploited in the wild PoC available

Recommended Action

Prioritize remediation. Validate affected assets and apply vendor fixes on an accelerated timeline.

Confidence
Confirmed
Exploitation Status
Exploited in the wild
Observed in Sensors
No
Attempts (30d)
Unique Attacker IPs
CISA KEV
In CISA KEV
CVSS / EPSS
7.8 High

At a Glance

Adobe Acrobat Reader versions 22.003.20282 (and earlier), 22.003.20281 (and earlier) and 20.005.30418 (and earlier) are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

cisa nessus_scanner
CVE Published
Jan 18, 2023
Exploitation Reported
Oct 10, 2023
CVSS
7.8 High
EPSS
Low complexity Unauthenticated

Affected Versions

Vendor Product Version Status
Adobe
Acrobat Reader

unspecified to <= 20.005.30418

Affected
Adobe
Acrobat Reader

unspecified to <= 22.003.20282

Affected
Adobe
Acrobat Reader

unspecified to <= 22.003.20281

Affected
Adobe
Acrobat Reader

unspecified to <= None

Affected

CVE References

Recommended Actions

  • Prioritize remediation. Validate affected assets and apply vendor fixes on an accelerated timeline.
  • Check enrichment artifacts for scanner coverage and available PoCs before rolling remediation validation.
  • Use the Pro API to automate enrichment, telemetry, and workflow delivery for VM, SOC, and CTI pipelines.