LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2023-26369: Adobe Acrobat and Reader Out-of-Bounds Write Vulnerability

RBRecent Breaches Vulnerability Intelligence·Sep 14, 2023
High⚠ Actively exploited (CISA KEV)
High
Severity
Active
CISA KEV
No
Ransomware use
Oct 5, 2023
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2023-26369 to its Known Exploited Vulnerabilities catalog on Sep 14, 2023, with a federal patch deadline of Oct 5, 2023 — meaning attackers are actively using it. If you run the affected software, patch it immediately.

Adobe Acrobat and Reader contains an out-of-bounds write vulnerability that allows for code execution.

CVE-2023-26369 is an out-of-bounds write vulnerability affecting Adobe Acrobat and Reader. It can allow an attacker who supplies crafted content to achieve code execution on a system running the software. These products are common on endpoints that open PDF and related documents, so the issue can turn routine file handling into a path for system compromise if left unaddressed.

Defenders should treat it as a high-priority desktop application risk. Confirm every technical detail against the current Adobe advisory before acting, because public summaries do not list exact version ranges or configurations here.

How it works

The weakness is classified as CWE-787, an out-of-bounds write. In this class of flaw, the application writes data past the end (or before the start) of an allocated memory buffer. That corruption can overwrite adjacent structures that control program flow, such as function pointers or return addresses.

An attacker abuses the condition by presenting specially prepared input that the vulnerable code path processes. When the out-of-bounds write occurs under attacker influence, it can redirect execution to code of the attacker’s choosing, resulting in arbitrary code execution in the context of the Acrobat or Reader process. The CISA summary states that the vulnerability allows for code execution; no further exploit mechanics are supplied in the available facts, so treat any deeper claims as unverified until the vendor advisory is reviewed.

Am I affected? How to find it in your systems

Adobe Acrobat and Reader typically run on Windows and macOS workstations, laptops, and virtual desktops used by knowledge workers, finance teams, legal staff, and anyone who routinely opens PDFs. They may also appear in automated document-processing servers or kiosks.

How to remediate

Patch first. Apply the vendor-supplied update for Adobe Acrobat and Reader exactly as described in Adobe’s advisory for this CVE. CISA’s required action is to apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.

If you can't patch immediately

Until the vendor update can be deployed, reduce exposure with compensating controls.

If your data may have been exposed

Vulnerabilities that permit code execution can be used to establish persistence, steal credentials, or move laterally, and such activity has led to data breaches in other cases. Known ransomware use of this specific CVE is not documented in the supplied facts. If you suspect compromise, isolate affected hosts, collect forensic images, and begin credential rotation and log review. Separately, you can run a free exposure scan of your email address against known breach data sets to check whether your credentials or personal information already appear in public dumps.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedAdobe · Acrobat and Reader
WeaknessCWE-787
Added to CISA KEVSep 14, 2023
Federal patch deadlineOct 5, 2023
Known ransomware useNot documented
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities