HIGH🇵🇱 Wersja polska

CVE-2023-29320

CVSS 7.8v3.1pub. 2023-08-10upd. 2024-11-21

Adobe Acrobat Reader versions 23.003.20244 (and earlier) and 20.005.30467 (and earlier) are affected by an Violation of Secure Design Principles vulnerability that could result in arbitrary code execution in the context of the current user by bypassing the API blacklisting feature. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

CVSS Vector
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
  • Adobe Acrobat

    APP
    Adobe
    20.001.30005 – 20.005.30516.1051620.001.30005 – 20.005.30514.10514 (excl.)
  • Adobe Acrobat DC

    APP
    Adobe
    15.008.20082 – 23.003.20269 (excl.)
  • Adobe Acrobat Reader

    APP
    Adobe
    20.001.30005 – 20.005.30516.10516 (excl.)20.001.30005 – 20.005.30514.10514 (excl.)
  • Adobe Acrobat Reader Dc

    APP
    Adobe
    15.008.20082 – 23.003.20269 (excl.)
  • Apple macOS

    OS
    Apple
    all versions
  • Microsoft Windows

    OS
    Microsoft
    all versions
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
RCE
CWE
References

Related vulnerabilities

CVE-2026-65400CRITICAL9.8⚠ KEVPL ✓same product

Pominięcie uwierzytelniania w Screen Sharing na macOS

CVE-2026-8398CRITICAL9.3⚠ KEVPL ✓same product

Atak na łańcuch dostaw DAEMON Tools Lite — trojanizacja instalatorów

CVE-2025-10585CRITICAL9.8⚠ KEVPL ✓same product

Type confusion w V8 (Google Chrome) — zdalne uszkodzenie sterty

CVE-2025-43300CRITICAL10.0⚠ KEVPL ✓same product

Apple iOS/iPadOS/macOS — out-of-bounds write przy przetwarzaniu obrazu

CVE-2025-34028CRITICAL9.3⚠ KEVPL ✓same product

Commvault Command Center – nieuwierzytelniony RCE przez path traversal w ZIP