First published: Thu Feb 11 2021(Updated: )
Acrobat Reader DC versions versions 2020.013.20074 (and earlier), 2020.001.30018 (and earlier) and 2017.011.30188 (and earlier) are affected by a use-after-free vulnerability. An unauthenticated attacker could leverage this vulnerability to achieve arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Credit: psirt@adobe.com
Affected Software | Affected Version | How to fix |
---|---|---|
Adobe Acrobat Reader | >=17.0<=17.011.30188 | |
Adobe Acrobat Reader | >=20.0<=20.001.30018 | |
Adobe Acrobat Reader DC | <=20.013.20074 | |
Adobe Acrobat Reader Notification Manager | >=17.0<=17.011.30188 | |
Adobe Acrobat Reader Notification Manager | >=20.0<=20.001.300183 | |
Adobe Acrobat Reader | <=20.013.20074 | |
macOS | ||
Microsoft Windows Operating System |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-21041 is classified as a critical severity vulnerability due to its potential to allow arbitrary code execution.
To fix CVE-2021-21041, update Adobe Acrobat Reader DC and Adobe Acrobat to the latest versions available.
CVE-2021-21041 affects Adobe Acrobat DC versions up to 20.013.20074 and specific versions of Adobe Acrobat Reader and Acrobat Reader DC.
CVE-2021-21041 can be exploited by unauthenticated attackers to execute arbitrary code.
CVE-2021-21041 impacts systems running affected versions of Adobe Acrobat Reader and Adobe Acrobat on both Windows and macOS.