Important Notice: Security Vulnerabilities of Adobe Acrobat and Acrobat Reader
重要通知 : 關於 Adobe Acrobat和Acrobat Reader 產品的安全漏洞通告
資訊安全警示 Information Security Alert
To: All Users
As informed by the Cybersecurity Incident Alert and Response Centre (CARIC), Adobe have recently issued a security vulnerability notice about Adobe Acrobat and Acrobat Reader. Attackers can use this vulnerability to trigger the execution of arbitrary code on the target system. There are signs that related vulnerabilities have been exploited recently. Please be reminded to to update as soon as possible.
Related vulnerabilities
Exploiting the weakness after memory reuse (CWE-416), attackers will create malicious documents and induce victims to open, which will trigger the arbitrary code execution attacks (CVE-2023-201608).
Affected Products:
- Acrobat DC and Scrobat Reader DC: 22.003.20282 (Win), 22.003.20281 (Mac) and previous versions
- Acrobat 2020 and Acrobat Reader 2020: 20.005.30418 and previous versions
For more details, please refer to: https://helpx.adobe.com/security/products/acrobat/apsb23-01.html
Mitigation
If the above-mentioned affected products are being used, please install the security updates released by Adobe as soon as possible and avoid opening any suspicious files.
Reference
- How to download and install software in a secure manner?
- Basic Knowledge of Online Safety and Security
- Other Information Security Tips
Should you have any enquiries, please feel free to contact ICTO Help Desk.
ICTO Help Desk
Location : Room 2085, 2/F, Central Teaching Building (E5), eMap
Telephone : 8822 8600
email : icto.helpdesk@um.edu.mo
Information and Communication Technology Office
各位用戶:
資訊及通訊科技部接獲網絡安全事故預警及應急中心的通知,Adobe公司發出有關於 Adobe Acrobat和Acrobat Reader的安全漏洞通告。攻擊者可利用此漏洞於目標系統觸發執行任意程式碼,相關漏洞近日有跡象顯示已被開發利用,建議盡早安排更新修復。
相關漏洞詳情
-
利用内存釋放後重用弱點(CWE-416),攻擊者製作惡意文檔並誘導受害者打開,從而觸發執行任意程式碼攻擊(CVE-2023-21608)。
受影響版本為:
- Acrobat DC和Acrobat Reader DC: 22.003.20282(Win), 22.003.20281(Mac)及以前版本
- Acrobat 2020和Acrobat Reader 2020: 20.005.30418及以前版本
有關詳情可參考:https://helpx.adobe.com/security/products/acrobat/apsb23-01.html
處置要求
- 倘有使用上述受影響產品,須盡快安裝由Adobe公司釋出的安全更新和避免打開任何可疑文檔。
參考資料
如有任何疑問,請聯絡資訊及通訊科技部服務中心。
服 務 中 心
位置 : 中央教學樓東5座(E5)二樓2085室 (電子地圖)
電話 : 8822 8600
電郵 : icto.helpdesk@um.edu.mo
資訊及通訊科技部