PatchSiren cyber security CVE debrief
CVE-2023-4662 Saphira CVE debrief
CVE-2023-4662 is a critical flaw in Adobe Connect as represented in the official NVD record, affecting versions before 9.0. The issue is described as execution with unnecessary privileges and remote code inclusion, with a CVSS 3.1 score of 9.8 and no privileges or user interaction required.
- Vendor
- Saphira
- Product
- Saphira Connect
- CVSS
- CRITICAL 9.8
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2023-09-15
- Original CVE updated
- 2026-05-21
- Advisory published
- 2023-09-15
- Advisory updated
- 2026-05-21
Who should care
Administrators and security teams responsible for Adobe Connect deployments, especially internet-facing instances, should prioritize this immediately.
Technical summary
The supplied NVD entry maps CVE-2023-4662 to Adobe Connect with a vulnerable range ending before 9.0. NVD rates it CVSS 3.1 9.8 (AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H), indicating a network-reachable issue with no attacker privileges or user interaction required. The record also lists CWE-269 (Improper Privilege Management) as the primary weakness and notes a secondary CWE-250 reference in the USOM advisory metadata. In defensive terms, the concern is that code can execute with privileges that should not be available, which can support remote code inclusion.
Defensive priority
Immediate: treat as a critical patching and exposure-reduction item for any affected Adobe Connect deployment.
Recommended defensive actions
- Upgrade Adobe Connect to version 9.0 or later, based on the supplied vulnerable range ending before 9.0.
- Inventory all Adobe Connect instances and confirm none remain in the affected version range.
- If immediate patching is not possible, restrict network access to Adobe Connect as tightly as operationally possible.
- Review USOM and NVD references for any additional vendor guidance tied to this CVE.
- Monitor for unexpected changes or suspicious activity in Adobe Connect deployments before and after remediation.
- Verify the update by rechecking the installed version and any exposed service endpoints.
Evidence notes
The official NVD record for CVE-2023-4662 was published on 2023-09-15 and modified on 2026-05-21. Its CPE criteria identify Adobe Connect as vulnerable when the version is below 9.0, and the CVSS vector is CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H. The record includes third-party advisory references from USOM and lists CWE-269 as primary weakness.
Sources and references
Verified primary and authoritative sources
-
CVE-2023-4662 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2023-4662
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2023-4662 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2023-4662
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://siberguvenlik.gov.tr/guvenlik-bildirimleri/detay/tr-23-0535
-
Mitigation or vendor reference
Unverified legacy reference
URL: https://www.usom.gov.tr/bildirim/tr-23-0535
[email protected] - Third Party Advisory
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.