EXPOSURES › CVE-2023-21608
CVE-2023-21608
HIGH ⌖ ON CISA KEV · EXPLOITEDAdobe Acrobat and Reader Use-After-Free Vulnerability
Adobe Acrobat and Reader contains a use-after-free vulnerability that allows for code execution in the context of the current user. This is a critical Remote Code Execution (RCE) vulnerability, exposing users to potential data theft and system compromise. DIB organizations should patch immediately and monitor for exploitation.
Shame score — Repetitive critical RCE vulnerabilities in Acrobat and Reader products, indicating a lack of adequate security measures and oversight.
▸ RECOMMENDED ACTION Actively exploited (CISA KEV) — remediate now, ahead of your normal patch cycle.
Adobe Acrobat and Reader contains a use-after-free vulnerability that allows for code execution in the context of the current user.
| PRODUCT | STATUS |
|---|---|
| Adobe Acrobat Sign for Government Adobe |
Authorized |
| Adobe Analytics Adobe |
Authorized |
| Adobe Campaign Adobe |
Authorized |
| Adobe Connect Managed Services (ACMS-GC) Adobe |
Authorized |
| Adobe Creative Cloud for Enterprise Adobe |
Authorized |
| Adobe Document Cloud (PDF Services & Adobe Sign) Adobe |
Authorized |
| Adobe Experience Manager Managed Services (AEMMS-GC) Adobe |
Authorized |
| Adobe Learning Manager Adobe |
Authorized |