{
  "crds_version": "0.1",
  "kind": "base",
  "id": "crds:cve-2023-21608",
  "revision": 1,
  "title": "Adobe Acrobat — a document that reuses freed memory",
  "summary": "A crafted document makes Adobe Acrobat and Reader use memory after releasing it, and code then runs as whoever opened the file. Versions 22.003.20282, 22.003.20281 and 20.005.30418 and earlier are affected.",
  "source_type": "cve",
  "severity": "high",
  "cvss": {
    "score": 7.8,
    "vector": "CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H",
    "version": "3.1"
  },
  "epss": 0.61475,
  "exploitation": {
    "known_exploited": true,
    "exploit_available": false,
    "attack_complexity": "low",
    "kev_added": "2023-10-10",
    "prerequisites": "The user must open a document the attacker supplied."
  },
  "remediation": {
    "patch_available": true
  },
  "mitre_attack": [
    "T1203"
  ],
  "kill_chain": "execution",
  "recommended_action": "Update Acrobat and Reader to the January 2023 releases, including the machines where Reader was installed once years ago and never looked at again.",
  "confidence": "high",
  "provenance": [
    {
      "fields": [
        "cvss",
        "exploitation.attack_complexity",
        "exploitation.exploit_available",
        "references",
        "published_at"
      ],
      "source": "https://nvd.nist.gov/vuln/detail/CVE-2023-21608",
      "retrieved_at": "2026-09-24T12:52:19.575Z",
      "confidence": "high",
      "extractor": "scrty-crds-pipeline/0.1"
    },
    {
      "fields": [
        "exploitation.known_exploited",
        "exploitation.kev_added"
      ],
      "source": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
      "retrieved_at": "2026-09-24T12:52:19.575Z",
      "confidence": "high",
      "extractor": "scrty-crds-pipeline/0.1"
    },
    {
      "fields": [
        "epss"
      ],
      "source": "https://api.first.org/data/v1/epss?cve=CVE-2023-21608",
      "retrieved_at": "2026-09-24T12:52:19.575Z",
      "confidence": "high",
      "extractor": "scrty-crds-pipeline/0.1"
    },
    {
      "fields": [
        "title",
        "summary",
        "severity",
        "remediation",
        "mitre_attack",
        "kill_chain",
        "recommended_action",
        "confidence",
        "tags",
        "exploitation.prerequisites"
      ],
      "source": "https://nvd.nist.gov/vuln/detail/CVE-2023-21608",
      "retrieved_at": "2026-09-24T12:52:19.575Z",
      "confidence": "high",
      "extractor": "claude-code"
    }
  ],
  "references": [
    {
      "type": "cve",
      "url": "https://nvd.nist.gov/vuln/detail/CVE-2023-21608",
      "label": "NVD record"
    },
    {
      "type": "cisa",
      "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog",
      "label": "CISA Known Exploited Vulnerabilities catalog"
    },
    {
      "type": "vendor_advisory",
      "url": "https://helpx.adobe.com/security/products/acrobat/apsb23-01.html"
    },
    {
      "type": "writeup",
      "url": "https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2023-21608"
    }
  ],
  "published_at": "2023-01-18T19:15:11.877Z",
  "issued_at": "2026-09-24T12:52:19.575Z",
  "tags": [
    "adobe",
    "acrobat",
    "reader",
    "use-after-free",
    "documents",
    "kev"
  ]
}
