CVE-2023-44328
CVSS 3.1 Score 5.5 of 10 (medium)
Details
Published Nov 16, 2023
Updated: Dec 4, 2023
CWE ID 416
Summary
CVE-2023-44328 is a Use After Free vulnerability affecting Adobe Bridge versions 13.0.4 and earlier, as well as 14.0.0 and earlier. This issue permits an attacker to manipulate memory in a way that could reveal sensitive information, bypassing Address Space Layout Randomization (ASLR) mitigations. The exploitation of this vulnerability necessitates user interaction, requiring the victim to open a malicious file.
Prevent cyber attacks with Recorded Future by prioritizing and patching critical vulnerabilities being exploited by threat actors targeting your industry. Book your demo to learn more.
Affected Products
- Adobe Bridge
Affected Vendors
- Adobe