October 10, 2023 · Applied Cybernetics Group
CVE-2023-21608 — Adobe Acrobat and Reader
Adobe Acrobat and Reader Use-After-Free Vulnerability
- Added to KEV
2023-10-10- Federal due date
2023-10-31- Vendor
- Adobe
- Product
- Acrobat and Reader
- EPSS
- 99.0th percentile (score 0.775, as of
2026-06-08) - NVD CVSS v3.1
- —
- Ransomware use
- Unknown
- Upstream
- https://nvd.nist.gov/vuln/detail/CVE-2023-21608
CISA short description
Adobe Acrobat and Reader contains a use-after-free vulnerability that allows for code execution in the context of the current user.
Required action
Apply mitigations per vendor instructions or discontinue use of the product if mitigations are unavailable.