Executive brief
Adobe Acrobat and Reader are affected by a use-after-free vulnerability that allows an unauthenticated attacker to execute arbitrary code. Exploitation requires a user to open a specially crafted malicious file.
Affected products
- Adobe Acrobat Reader DC 2021.001.20150 (and earlier)
- Adobe Acrobat Reader DC 2020.001.30020 (and earlier)
- Adobe Acrobat Reader DC 2017.011.30194 (and earlier)
- Adobe Acrobat DC 21.001.20150 (and earlier)
Timeline
- 2021-11-03: disclosed
- 2021-11-03: kev added: Added to CISA Known Exploited Vulnerabilities Catalog
- 2021-11-03: exploited: Reported as exploited in the wild at time of publication.