Executive brief
Adobe Acrobat and Reader are vulnerable to a heap-based buffer overflow when processing malicious files. An unauthenticated attacker can achieve arbitrary code execution in the context of the current user if a victim opens a specially crafted file.
Affected products
- Adobe Acrobat Reader DC 2020.013.20074 (and earlier)
- Adobe Acrobat Reader DC 2020.001.30018 (and earlier)
- Adobe Acrobat Reader DC 2017.011.30188 (and earlier)
- Adobe Acrobat DC 2020.013.20074 (and earlier)
- Adobe Acrobat Classic 2020.001.30018 (and earlier)
- Adobe Acrobat Classic 2017.011.30188 (and earlier)
Timeline
- 2021-02-11: disclosed: NVD Published Date
- 2021-11-03: kev added: Date added to CISA Known Exploited Vulnerabilities Catalog
- 2021-11-03: exploited: Reported exploited in the wild