

Rewterz Threat Alert – ‘NewsPenguin’ Threat Actors Targeting Pakistani Entities With Malicious Campaign – Active IOCs
February 9, 2023
Rewterz Threat Advisory – Multiple Google Chrome Vulnerabilities
February 10, 2023
Rewterz Threat Alert – ‘NewsPenguin’ Threat Actors Targeting Pakistani Entities With Malicious Campaign – Active IOCs
February 9, 2023
Rewterz Threat Advisory – Multiple Google Chrome Vulnerabilities
February 10, 2023Severity
High
Analysis Summary
CVE-2023-22240 CVSS:7.8
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Adobe Acrobat Reader DC. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of Annotation objects. By performing actions in JavaScript, an attacker can trigger a write past the end of an allocated object. An attacker can leverage this vulnerability to execute code in the context of the current process.
CVE-2023-22241 CVSS:7.8
Adobe Acrobat and Adobe Reader could allow a remote attacker to execute arbitrary code on the system, caused by an out-of-bounds write error. By persuading a victim to open a specially-crafted document, an attacker could exploit this vulnerability to execute arbitrary code on the system with the privileges of the victim or cause the application to crash.
CVE-2023-22242 CVSS:7.8
Adobe Acrobat and Adobe Reader could allow a remote attacker to execute arbitrary code on the system, caused by an out-of-bounds write error. By persuading a victim to open a specially-crafted document, an attacker could exploit this vulnerability to execute arbitrary code on the system with the privileges of the victim or cause the application to crash.
Impact
- Code Execution
Indicators Of Compromise
CVE
- CVE-2023-22240
- CVE-2023-22241
- CVE-2023-22242
Affected Vendors
Adobe
Affected Products
- Adobe Acrobat DC 22.003.20281
- Adobe Acrobat DC 22.003.20282
- Adobe Acrobat Reader DC 22.003.20282
- Adobe Acrobat Reader DC 22.003.20281
- Adobe Acrobat 2020 20.005.30418
- Adobe Acrobat Reader 2020 20.005.30418
Remediation
Refer to Adobe Security Advisory for patch, upgrade or suggested workaround information.