Vulnerability record · CVE-2023-26369 · published 13 September 2023
CVE-2023-26369: Adobe Acrobat and Reader out-of-bounds write allows code execution
Adobe · Acrobat
Adobe Acrobat and Reader versions 23.003.20284, 20.005.30516 and 20.005.30514 (and earlier) contain an out-of-bounds write (CWE-787) that can lead to arbitrary code execution in the context of the current user. The flaw is triggered when a victim opens a malicious file, so it is a client-side code execution issue in a widely deployed document reader.
Description
Acrobat Reader versions 23.003.20284 (and earlier), 20.005.30516 (and earlier) and 20.005.30514 (and earlier) are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Automated analysis
high priorityThe flaw allows code execution in a widely used client, is listed in CISA KEV as exploited in the wild, and has a high EPSS percentile, though it requires user interaction.
What it is
Adobe Acrobat and Reader versions 23.003.20284, 20.005.30516 and 20.005.30514 (and earlier) contain an out-of-bounds write (CWE-787) that can lead to arbitrary code execution in the context of the current user. The flaw is triggered when a victim opens a malicious file, so it is a client-side code execution issue in a widely deployed document reader.
Impact
An attacker who gets a victim to open a crafted file can execute arbitrary code with the privileges of the current user. That enables malware installation, data theft or further compromise of the user's system.
Attack surface
Reached locally through a malicious file opened in Acrobat or Reader; the CVSS vector shows AV:L, PR:N and UI:R, so no authentication is needed but user interaction (opening the file) is required.
Exploitation
CVE-2023-26369 was added to CISA KEV on 2023-09-14, indicating known exploitation in the wild; EPSS 30-day probability is about 7.1% (93.9th percentile). No ransomware campaign use is documented in the record.
What to do
- Apply the Adobe security update for APSB23-34 to Acrobat, Acrobat DC, Acrobat Reader and Acrobat Reader DC as soon as possible.
- If patching cannot be completed immediately, follow CISA KEV required action: apply vendor mitigations or discontinue use of the affected product.
- Enforce automatic updates for Acrobat and Reader and verify installed versions are above the affected builds.
- Restrict or block untrusted PDF and document attachments at email and web gateways where feasible.
- Educate users not to open unexpected or unsolicited PDF files from unknown senders.
Detection
- Hunt for Acrobat or Reader processes spawning child processes such as cmd.exe, powershell.exe or scripting hosts, which is abnormal for normal PDF viewing.
- Monitor for document files written to temp or user directories followed by execution of dropped binaries.
- Review endpoint telemetry for crashes or memory corruption events in Acrobat/Reader that may indicate exploitation attempts.
- Check email and web proxy logs for PDF attachments or downloads from untrusted sources delivered to users running affected versions.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2023-26369 to the Known Exploited Vulnerabilities catalog on 14 September 2023 as "Adobe Acrobat and Reader Out-of-Bounds Write Vulnerability". Required action: Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable. Federal deadline 5 October 2023.
Affected products
4 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://helpx.adobe.com/security/products/acrobat/apsb23-34.html | Vendor Advisory |
| https://helpx.adobe.com/security/products/acrobat/apsb23-34.html | Vendor Advisory |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2023-26369 | Third Party AdvisoryUS Government Resource |
Track CVE-2023-26369 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2023-26369), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.