HIGH🇵🇱 Wersja polska

CVE-2023-21612

CVSS 7.8v3.1pub. 2023-01-18upd. 2024-11-21

Adobe Acrobat Reader versions 22.003.20282 (and earlier), 22.003.20281 (and earlier) and 20.005.30418 (and earlier) are affected by a Creation of Temporary File in Directory with Incorrect Permissions vulnerability that could result in privilege escalation in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

CVSS Vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
  • Adobe Acrobat

    APP
    Adobe
    20.001.30005 – 20.005.30418
  • Adobe Acrobat DC

    APP
    Adobe
    15.008.20082 – 22.003.2028115.008.20082 – 22.003.20282
  • Adobe Acrobat Reader

    APP
    Adobe
    20.001.30005 – 20.005.30418
  • Adobe Acrobat Reader Dc

    APP
    Adobe
    15.008.20082 – 22.003.2028115.008.20082 – 22.003.20282
  • Apple macOS

    OS
    Apple
    all versions
  • Microsoft Windows

    OS
    Microsoft
    all versions
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
LPE
CWE
References

Related vulnerabilities

CVE-2026-65400CRITICAL9.8⚠ KEVPL ✓same product

Pominięcie uwierzytelniania w Screen Sharing na macOS

CVE-2026-8398CRITICAL9.3⚠ KEVPL ✓same product

Atak na łańcuch dostaw DAEMON Tools Lite — trojanizacja instalatorów

CVE-2025-10585CRITICAL9.8⚠ KEVPL ✓same product

Type confusion w V8 (Google Chrome) — zdalne uszkodzenie sterty

CVE-2025-43300CRITICAL10.0⚠ KEVPL ✓same product

Apple iOS/iPadOS/macOS — out-of-bounds write przy przetwarzaniu obrazu

CVE-2025-34028CRITICAL9.3⚠ KEVPL ✓same product

Commvault Command Center – nieuwierzytelniony RCE przez path traversal w ZIP