CVE-2023-21608 is a critical Use After Free vulnerability in Adobe Acrobat and Reader (versions 22.003.20282 and earlier, 20.005.30418 and earlier) that allows for arbitrary code execution in the context of the current user. This vulnerability, affecting Adobe, Apple, and Microsoft platforms, requires user interaction to open a malicious file. It carries a high CVSS score of 7.8, indicating a significant impact with high confidentiality, integrity, and availability risks. Notably, this CVE is actively exploited in the wild, as confirmed by its presence in the CISA KEV catalog, and has garnered substantial community discussion and media coverage despite a lack of public exploit code.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 15.008.20082, <= 22.003.20282CPE matchmatch criteria | cpe:2.3:a:adobe:acrobat_dc:*:*:*:*:continuous:*:*:* | ||
>= 15.008.20082, <= 22.003.20282CPE matchmatch criteria | cpe:2.3:a:adobe:acrobat_reader_dc:*:*:*:*:continuous:*:*:* | ||
>= 15.008.20082, <= 22.003.20281CPE matchmatch criteria | cpe:2.3:a:adobe:acrobat_dc:*:*:*:*:continuous:*:*:* | ||
>= 15.008.20082, <= 22.003.20281CPE matchmatch criteria | cpe:2.3:a:adobe:acrobat_reader_dc:*:*:*:*:continuous:*:*:* | ||
>= 20.001.30005, <= 20.005.30418CPE matchmatch criteria | cpe:2.3:a:adobe:acrobat:*:*:*:*:classic:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.