← Vulnerability feed

Vulnerability record · CVE-2023-21608 · published 18 January 2023

CVE-2023-21608: Adobe Acrobat Reader use-after-free allows arbitrary code execution

Adobe · Acrobat Dc

Adobe Acrobat and Reader are affected by a use-after-free (CWE-416) that can lead to arbitrary code execution in the context of the current user. The flaw is reachable by opening a malicious file, so it is a classic client-side document attack against users who handle untrusted PDFs. It matters because the affected products are widely deployed and the issue is listed in CISA KEV.

7.8 CVSS 3.1 High CISA KEV since 10 Oct 2023 EPSS 61% · top 0.9% CWE-416 · Use after free
7.8CVSS 3.1 base score
61%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
4Affected product versions listed by NVD
3References
17 Jun 2026Last modified by NVD

Description

Adobe Acrobat Reader versions 22.003.20282 (and earlier), 22.003.20281 (and earlier) and 20.005.30418 (and earlier) are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 17 September 2026. Confidence: high.

high priorityThe flaw gives code execution with user interaction, is listed in CISA KEV with a near-term remediation deadline, and has very high EPSS probability, though it requires a victim to open a file.

What it is

Adobe Acrobat and Reader are affected by a use-after-free (CWE-416) that can lead to arbitrary code execution in the context of the current user. The flaw is reachable by opening a malicious file, so it is a classic client-side document attack against users who handle untrusted PDFs. It matters because the affected products are widely deployed and the issue is listed in CISA KEV.

Impact

An attacker who gets a victim to open a crafted file can execute arbitrary code with the victim's privileges, giving full control of confidentiality, integrity and availability for that user session.

Attack surface

Reached locally through a malicious file opened in Acrobat or Reader; the CVSS vector shows no privileges required but user interaction is required, so the victim must open the crafted document.

Exploitation

CVE-2023-21608 is in CISA KEV with a 2023-10-31 remediation due date, and EPSS shows a 30-day probability of about 0.61 (99th percentile), indicating active exploitation and high likelihood. No ransomware campaign use is recorded.

What to do

  • Apply the Adobe security update for APSB23-01 to all Acrobat and Reader installations, prioritizing versions 22.003.20282, 22.003.20281 and 20.005.30418 and earlier.
  • If patching cannot be completed immediately, follow CISA KEV guidance to apply vendor mitigations or discontinue use of the affected product.
  • Restrict or block untrusted PDF attachments at email and web gateways, and disable automatic opening of PDFs from external sources.
  • Run Acrobat and Reader with least privilege and enable Protected View or equivalent sandboxing where available.

Detection

  • Monitor for Acrobat or Reader processes spawning child processes such as cmd.exe, powershell.exe or scripting hosts, which is abnormal for document viewing.
  • Hunt for PDF files written to temp or download directories followed by Acrobat/Reader execution and outbound network connections.
  • Review endpoint telemetry for crashes or memory corruption in Acrobat/Reader that precede suspicious process creation.
  • Check for the specific affected version strings in software inventory to find unpatched hosts.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2023-21608 to the Known Exploited Vulnerabilities catalog on 10 October 2023 as "Adobe Acrobat and Reader Use-After-Free Vulnerability". Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. Federal deadline 31 October 2023.

Affected products

4 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2023-21608 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2014-0546Adobe Reader and Acrobat sandbox bypass allows privileged code executionAdobe Reader and Acrobat 10.x before 10.1.11 and 11.x before 11.0.08 on Windows contain a sandbox protection bypass. An attacker can escape the Reade…KEVEPSS 22%analysed9.8CVE-2013-3346Adobe Reader and Acrobat memory corruption allows code executionAdobe Reader and Acrobat 9.x before 9.5.5, 10.x before 10.1.7, and 11.x before 11.0.03 contain an out-of-bounds write (CWE-787) that corrupts memory.…KEVEPSS 79%analysed9.8CVE-2013-2729Adobe Reader and Acrobat integer overflow allows code executionAdobe Reader and Acrobat contain an integer overflow (CWE-190) that can be triggered by unspecified vectors, leading to arbitrary code execution. It …KEVEPSS 67%analysed9.8CVE-2011-2462Adobe Reader and Acrobat U3D memory corruption code executionAn out-of-bounds write in the U3D component of Adobe Reader and Acrobat allows remote attackers to corrupt memory and execute arbitrary code. The fla…KEVEPSS 89%analysed8.8CVE-2021-28550Adobe Acrobat and Reader use-after-free allows code executionAdobe Acrobat Reader DC (2021.001.20150, 2020.001.30020, 2017.011.30194 and earlier) and related Acrobat products contain a use-after-free (CWE-416) …KEVEPSS 52%analysed8.8CVE-2021-21017Adobe Acrobat and Reader heap buffer overflow via malicious fileAdobe Acrobat Reader DC (2020.013.20074, 2020.001.30018, 2017.011.30188 and earlier) contains a heap-based buffer overflow (CWE-122/CWE-787) triggere…KEVEPSS 86%analysed8.8CVE-2018-4990Adobe Acrobat and Reader double free allows code executionAdobe Acrobat and Reader contain a double free (CWE-415) in versions 2018.011.20038 and earlier, 2017.011.30079 and earlier, and 2015.006.30417 and e…KEVEPSS 36%analysed8.8CVE-2014-0496Adobe Reader and Acrobat use-after-free code executionAdobe Reader and Acrobat 10.x before 10.1.9 and 11.x before 11.0.06 on Windows and Mac OS X contain a use-after-free (CWE-416) that allows arbitrary …KEVEPSS 40%analysed

Source: NIST National Vulnerability Database (record CVE-2023-21608), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.