CVE-2023-28500 is a critical insecure deserialization vulnerability in Adobe LiveCycle ES4 version 11.0 and earlier, potentially affecting later versions if running Java 7u21 or older. Unauthenticated remote attackers can achieve operating system code execution by submitting specially crafted Java serialized objects. With a CVSS score of 9.8, this vulnerability allows for complete compromise of confidentiality, integrity, and availability with low attack complexity. Despite its critical severity, there is no evidence of active exploitation, publicly available exploit code, or significant community discussion, likely due to the affected product being end-of-life.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 11.0.1CPE matchmatch criteria | cpe:2.3:a:adobe:livecycle_es4:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.