CVE-2023-29299 is a medium-severity vulnerability rated 4.7/10 on the CVSS scale. Adobe Acrobat Reader versions 23.003.20244 (and earlier) and 20.005.30467 (and earlier) are affected by an Untrusted Search Path vulnerability that could lead to Application denial-of-service. An attacker could leverage this vulnerability if the default PowerShell Set-ExecutionPolicy is set to Unrestricted, making the attack complexity high. EPSS estimates a 0.30% chance of exploitation in the next 30 days.

## Description

Adobe Acrobat Reader versions 23.003.20244 (and earlier) and 20.005.30467 (and earlier) are affected by an Untrusted Search Path vulnerability that could lead to Application denial-of-service. An attacker could leverage this vulnerability if the default PowerShell Set-ExecutionPolicy is set to Unrestricted, making the attack complexity high. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

## Metrics

CVSS 3.14.7/10

CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:N/I:N/A:H

EPSS Probability 0.30%

21.6th percentile

Probability of exploitation in the next 30 days. [Learn more](https://www.first.org/epss/)

## Weakness Enumeration

- [CWE-426](https://cwe.mitre.org/data/definitions/426.html)

## Affected Software

| Vendor | Product | Versions |
| --- | --- | --- |
| Adobe | Acrobat Dc | >= 15.008.20082, < 23.003.20269 |
| Adobe | Acrobat Reader Dc | >= 15.008.20082, < 23.003.20269 |
| Adobe | Acrobat | >= 20.001.30005, <= 20.005.30516.10516 |
| Adobe | Acrobat Reader | >= 20.001.30005, < 20.005.30516.10516 |
| Adobe | Acrobat | >= 20.001.30005, < 20.005.30514.10514 |
| Adobe | Acrobat Reader | >= 20.001.30005, < 20.005.30514.10514 |

## References

- [Adobe Release Notes and Vendor Advisory](https://helpx.adobe.com/security/products/acrobat/apsb23-30.html)

## Timeline

Published Aug 10, 2023

Last Modified Jun 17, 2026

Status Modified

## Frequently Asked Questions

**What is CVE-2023-29299?**

**How severe is CVE-2023-29299?**

CVE-2023-29299 has a CVSS score of 4.7/10 (MEDIUM severity). The EPSS model estimates a 0.30% probability of exploitation in the next 30 days.

**How do I fix CVE-2023-29299?**

Check the vendor references and advisories linked above for patched versions and mitigation guidance. You can also [run a Strix scan](https://app.strix.ai/) to test if your systems are affected.
