Vulnerability record · CVE-2023-21608 · published 18 January 2023
CVE-2023-21608: Adobe Acrobat Reader use-after-free allows arbitrary code execution
Adobe · Acrobat Dc
Adobe Acrobat and Reader are affected by a use-after-free (CWE-416) that can lead to arbitrary code execution in the context of the current user. The flaw is reachable by opening a malicious file, so it is a classic client-side document attack against users who handle untrusted PDFs. It matters because the affected products are widely deployed and the issue is listed in CISA KEV.
Description
Adobe Acrobat Reader versions 22.003.20282 (and earlier), 22.003.20281 (and earlier) and 20.005.30418 (and earlier) are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Automated analysis
high priorityThe flaw gives code execution with user interaction, is listed in CISA KEV with a near-term remediation deadline, and has very high EPSS probability, though it requires a victim to open a file.
What it is
Adobe Acrobat and Reader are affected by a use-after-free (CWE-416) that can lead to arbitrary code execution in the context of the current user. The flaw is reachable by opening a malicious file, so it is a classic client-side document attack against users who handle untrusted PDFs. It matters because the affected products are widely deployed and the issue is listed in CISA KEV.
Impact
An attacker who gets a victim to open a crafted file can execute arbitrary code with the victim's privileges, giving full control of confidentiality, integrity and availability for that user session.
Attack surface
Reached locally through a malicious file opened in Acrobat or Reader; the CVSS vector shows no privileges required but user interaction is required, so the victim must open the crafted document.
Exploitation
CVE-2023-21608 is in CISA KEV with a 2023-10-31 remediation due date, and EPSS shows a 30-day probability of about 0.61 (99th percentile), indicating active exploitation and high likelihood. No ransomware campaign use is recorded.
What to do
- Apply the Adobe security update for APSB23-01 to all Acrobat and Reader installations, prioritizing versions 22.003.20282, 22.003.20281 and 20.005.30418 and earlier.
- If patching cannot be completed immediately, follow CISA KEV guidance to apply vendor mitigations or discontinue use of the affected product.
- Restrict or block untrusted PDF attachments at email and web gateways, and disable automatic opening of PDFs from external sources.
- Run Acrobat and Reader with least privilege and enable Protected View or equivalent sandboxing where available.
Detection
- Monitor for Acrobat or Reader processes spawning child processes such as cmd.exe, powershell.exe or scripting hosts, which is abnormal for document viewing.
- Hunt for PDF files written to temp or download directories followed by Acrobat/Reader execution and outbound network connections.
- Review endpoint telemetry for crashes or memory corruption in Acrobat/Reader that precede suspicious process creation.
- Check for the specific affected version strings in software inventory to find unpatched hosts.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2023-21608 to the Known Exploited Vulnerabilities catalog on 10 October 2023 as "Adobe Acrobat and Reader Use-After-Free Vulnerability". Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. Federal deadline 31 October 2023.
Affected products
4 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://helpx.adobe.com/security/products/acrobat/apsb23-01.html | Vendor Advisory |
| https://helpx.adobe.com/security/products/acrobat/apsb23-01.html | Vendor Advisory |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2023-21608 | Third Party AdvisoryUS Government Resource |
Track CVE-2023-21608 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2023-21608), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.