QID 379013

Date Published: 2023-11-15

QID 379013: Adobe Acrobat and Reader Arbitrary Code Execution Vulnerability (APSB23-54)

Adobe Acrobat and Reader are applications for handling PDF files developed and marketed by Adobe Systems.

Affected Versions:
Adobe Acrobat DC - Continuous - 23.006.20360 and prior Windows and MacOS
Adobe Acrobat Reader DC - Continuous - 23.006.20360 and prior Windows and MacOS
Adobe Acrobat 2020 - Classic 2020 - 20.005.30524 and prior Windows and MacOS
Adobe Acrobat Reader 2020 - Classic 2020 - 20.005.30524 and prior Windows and MacOS

QID Detection Logic:(Authenticated)
This QID checks vulnerable versions of Adobe Acrobat and Reader.

Successful exploitation could lead to arbitrary code execution and memory leak.

  • CVSS V3 rated as Critical - 8.6 severity.
  • CVSS V2 rated as Medium - 5.4 severity.
  • Solution

    Adobe has released fix to address this issue. Customers are advised to refer to APSB23-54 for updates pertaining to this vulnerability.

    Software Advisories
    Advisory ID Software Component Link
    APSB23-54 URL Logo helpx.adobe.com//security/products/acrobat/apsb23-54.html