CVE-2021-21041: Acrobat Reader DC Use-After-Free Vulnerability Could Lead To Arbitrary Code Execution
Acrobat Reader DC versions versions 2020.013.20074 (and earlier), 2020.001.30018 (and earlier) and 2017.011.30188 (and earlier) are affected by a use-after-free vulnerability. An unauthenticated attacker could leverage this vulnerability to achieve arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2021-21041?
CVE-2021-21041 is classified as a critical severity vulnerability due to its potential to allow arbitrary code execution.
How do I fix CVE-2021-21041?
To fix CVE-2021-21041, update Adobe Acrobat Reader DC and Adobe Acrobat to the latest versions available.
What software versions are affected by CVE-2021-21041?
CVE-2021-21041 affects Adobe Acrobat DC versions up to 20.013.20074 and specific versions of Adobe Acrobat Reader and Acrobat Reader DC.
Who can exploit CVE-2021-21041?
CVE-2021-21041 can be exploited by unauthenticated attackers to execute arbitrary code.
What systems are impacted by CVE-2021-21041?
CVE-2021-21041 impacts systems running affected versions of Adobe Acrobat Reader and Adobe Acrobat on both Windows and macOS.