Junglewise Threat Intelligence

CVE-2021-21017: Adobe Acrobat and Reader Heap-based Buffer Overflow Vulnerability

CVE-2021-21017 · Severity: critical · CVSS 8.8 · Exploited in the wild · Published 2021-11-03

Technologies: Adobe Acrobat, Adobe Reader, Adobe Acrobat Reader Dc, Adobe Acrobat Dc. Vendors: Adobe.

Executive brief

Adobe Acrobat and Reader are vulnerable to a heap-based buffer overflow when processing malicious files. An unauthenticated attacker can achieve arbitrary code execution in the context of the current user if a victim opens a specially crafted file.

Affected products

  • Adobe Acrobat Reader DC 2020.013.20074 (and earlier)
  • Adobe Acrobat Reader DC 2020.001.30018 (and earlier)
  • Adobe Acrobat Reader DC 2017.011.30188 (and earlier)
  • Adobe Acrobat DC 2020.013.20074 (and earlier)
  • Adobe Acrobat Classic 2020.001.30018 (and earlier)
  • Adobe Acrobat Classic 2017.011.30188 (and earlier)

Timeline

  • 2021-02-11: disclosed: NVD Published Date
  • 2021-11-03: kev added: Date added to CISA Known Exploited Vulnerabilities Catalog
  • 2021-11-03: exploited: Reported exploited in the wild

Related threats