VDB
CVE-2023-26369
CVE-2023-26369
PUBLISHED
KEV
CVSS 7.800000190734863 HIGH
Adobe has released a security update for Adobe Acrobat and Reader for Windows and macOS. This update addresses a critical vulnerability. Successful exploitation could lead to arbitrary code execution . Adobe is aware that CVE-2023-26369 has been exploited in the wild in limited attacks targeting Adobe Acrobat and Reader. Vulnerability: Out-of-bounds Write (CWE-787) Impact: Arbitrary code execution Severity: Critical CVSS: 7.8 CWE: CWE-787
EPSS 7.06% · 93.8th percentile
Risk Scores
CVSS 3.1
7.800000190734863
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
EPSS Score
7.06%
93.8th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Adobe | Acrobat Reader DC | 23.003.20284, 23.003.20284, 23.003.20284 |
| Adobe | Acrobat DC | 23.003.20284, 23.003.20284, 23.003.20284 |
| Adobe | Acrobat Reader 2020 | 20.005.30516, 20.005.30516, 20.005.30516 |
| Adobe | Acrobat 2020 | 20.005.30516, 20.005.30516, 20.005.30516 |
Timeline
- Sep 12, 2023 CVE Published
- Sep 12, 2023 VulnCheck KEV Exploitation
- Sep 12, 2023 PoC Published
- Sep 13, 2023 VulnCheck KEV Exploitation
- Sep 13, 2023 EPSS Score
- Sep 13, 2023 PoC Published
- Sep 14, 2023 CISA KEV Added
- Sep 14, 2023 VulnCheck KEV Exploitation
- Sep 14, 2023 PoC Published
- Sep 16, 2023 EPSS Score
- Sep 18, 2023 EPSS Score
- Oct 17, 2023 VulnCheck KEV Exploitation