Adobe Acrobat Reader Vulnerable to Use After Free Vulnerability
CVE-2023-21608
Key Information:
- Vendor
- Adobe
- Status
- Vendor
- CVE Published:
- 18 January 2023
Badges
Summary
Adobe Acrobat Reader is affected by a Use After Free vulnerability that can lead to arbitrary code execution in the context of the user running the software. The exploitation of this vulnerability necessitates user engagement, specifically requiring the opening of a malicious file by the victim. Affected versions include Adobe Acrobat Reader 22.003.20282 and earlier, 22.003.20281 and earlier, as well as 20.005.30418 and earlier, posing a significant security risk to users who may inadvertently open compromised PDF files.
CISA Reported
CISA provides regional cyber and physical services to support security and resilience across the United States. CISA monitor the most dangerious vulnerabilities and have identifed as being exploited but is not known by the CISA to be used in ransomware campaigns. This is subject to change at pace
The CISA's recommendation is: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.
Affected Version(s)
Acrobat Reader <= 20.005.30418
Acrobat Reader <= 22.003.20282
Acrobat Reader <= 22.003.20281
Exploit Proof of Concept (PoC)
PoC code is written by security researchers to demonstrate the vulnerability can be exploited. PoC code is also a key component for weaponization which could lead to ransomware.
News Articles
์ด๋๋น ์ํฌ๋ก๋ฑ ๋ฆฌ๋์ ์ทจ์ฝ์ , ํ๋ฐํ ๊ณต๊ฒฉ ๋ฐ๊ณ ์์ด
๋ณด์ ์ธ์ ํด์ปค๋ด์ค์ ์ํ๋ฉด ๋ฏธ๊ตญ์ ์ฌ์ด๋ฒ ๋ณด์ ์ ๋ด ๊ธฐ๊ด์ธ CISA๊ฐ ์ด๋๋น ์ํฌ๋ก๋ฑ ๋ฆฌ๋(Adobe Acrobat Reader)์์ ๋ฐ๊ฒฌ๋ ์ทจ์ฝ์ ์ธ CVE-2023-21608์ ๋ํ ์๋ก์ด ๊ฒฝ๊ณ ๋ฅผ ๋ฐํํ๋ค๊ณ ํ๋ค. ํด๋น ์ทจ์ฝ์ ์ ํตํ ์ต์คํ๋ก์ ๊ณต๊ฒฉ์ด ํ๋ฐํ ์งํ๋๊ณ ์๋ค๋ ๊ฒ์ผ๋ก, CISA๋ ์ด ์ทจ์ฝ์ ์ โ๊ธด๊ธ ํจ์น ๋ชฉ๋ก(KEV)โ์ ํฌํจ์ํค๊ธฐ๋ ํ๋ค. CISA์ KEV ๋ชฉ๋ก์ ์ค์ง์ ์ธ ํดํน ๊ณต๊ฒฉ์ ํ์ฉ๋๊ณ ์๋ ์ทจ์ฝ์ ๋ค์ ํฌํจํ๊ณ ์์ด ํจ์น ๊ด๋ฆฌ ์ ์ฐธ๊ณ ํ๋ฉด ์ ์ฉํ๋ค๊ณ ์๋ ค์ ธ ์๋ค.
5 months ago
CISA Warns of Actively Exploited Adobe Acrobat Reader Vulnerability
Adobe Acrobat Reader users, beware! CISA adds high-severity flaw in Adobe Acrobat Reader to its Known Exploited Vulnerabilities list.
1 year ago
References
EPSS Score
3% chance of being exploited in the next 30 days.
CVSS V3.1
Timeline
- ๐ฐ
First article discovered by Security Affairs
- ๐ฆ
CISA Reported
- ๐ก
Public PoC available
- ๐พ
Exploit known to exist
Vulnerability published
Vulnerability Reserved