CVE-2023-29320: high-severity vulnerability in Adobe Acrobat Reader
ZDI-CAN-20712: Adobe Acrobat Blacklist Bypass Design flaw
Published · Updated
No sign of exploitation. No public exploitation artifact known so far.
Adobe Acrobat Reader has a security bypass that allows attackers to run malicious code on your computer by getting you to open a specially crafted PDF file. The software's built-in safety restrictions can be circumvented to execute harmful commands.
A design flaw in Adobe Acrobat Reader (versions 23.003.20244 and earlier, 20.005.30467 and earlier) allows attackers to bypass API blacklist restrictions, enabling arbitrary code execution in the user's context. The attack vector requires social engineering to trick a user into opening a malicious PDF file; once opened, the blacklist bypass permits execution of otherwise restricted APIs.
In the same product, most dangerous first.