CVE-2023-21608
HIGH KEVAdobe Acrobat Reader <22.003.20282 - Use After Free
Title source: llmExploitation Summary
CVE-2023-21608 is actively exploited and listed in the CISA Known Exploited Vulnerabilities (KEV) catalog, added October 10, 2023. EIP tracks 2 public exploits from researchers including hacksysteam, Malwareman007.
AI-analyzed exploit summary This repository contains a working proof-of-concept exploit for CVE-2023-21608, a use-after-free vulnerability in Adobe Acrobat Reader. The exploit leverages memory corruption to achieve remote code execution (RCE) by manipulating object references during a resetForm operation.
Description
Adobe Acrobat Reader versions 22.003.20282 (and earlier), 22.003.20281 (and earlier) and 20.005.30418 (and earlier) are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Exploits (2)
This repository contains a working proof-of-concept exploit for CVE-2023-21608, a use-after-free vulnerability in Adobe Acrobat Reader. The exploit leverages memory corruption to achieve remote code execution (RCE) by manipulating object references during a resetForm operation.
This repository contains a working proof-of-concept exploit for CVE-2023-21608, a use-after-free vulnerability in Adobe Acrobat Reader that leads to remote code execution. The exploit leverages JavaScript within a PDF to trigger the vulnerability, manipulate memory, and achieve arbitrary code execution.
References (2)
Scores
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H