Junglewise Threat Intelligence

CVE-2021-28550: Adobe Acrobat and Reader Use-After-Free Vulnerability

CVE-2021-28550 · Severity: critical · CVSS 8.8 · Exploited in the wild · Published 2021-11-03

Technologies: Adobe Acrobat, Adobe Acrobat Reader Dc, Adobe Reader, Adobe Acrobat Dc. Vendors: Adobe.

Executive brief

Adobe Acrobat and Reader are affected by a use-after-free vulnerability that allows an unauthenticated attacker to execute arbitrary code. Exploitation requires a user to open a specially crafted malicious file.

Affected products

  • Adobe Acrobat Reader DC 2021.001.20150 (and earlier)
  • Adobe Acrobat Reader DC 2020.001.30020 (and earlier)
  • Adobe Acrobat Reader DC 2017.011.30194 (and earlier)
  • Adobe Acrobat DC 21.001.20150 (and earlier)

Timeline

  • 2021-11-03: disclosed
  • 2021-11-03: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
  • 2021-11-03: exploited: Reported as exploited in the wild at time of publication.

Related threats