CVE-2021-28545: Acrobat Reader DC Missing Support for Integrity Check
Acrobat Reader DC versions versions 2020.013.20074 (and earlier), 2020.001.30018 (and earlier) and 2017.011.30188 (and earlier) are missing support for an integrity check. An unauthenticated attacker would have the ability to completely manipulate data in a certified PDF without invalidating the original certification. Exploitation of this issue requires user interaction in that a victim must open the tampered file.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2021-28545?
CVE-2021-28545 is considered a critical vulnerability due to its potential for unauthenticated data manipulation in certified PDFs.
How do I fix CVE-2021-28545?
To fix CVE-2021-28545, update Adobe Acrobat Reader DC or Adobe Acrobat to the latest version that addresses this vulnerability.
Which versions of Adobe Acrobat are affected by CVE-2021-28545?
CVE-2021-28545 affects Adobe Acrobat Reader DC versions up to 2020.013.20074, 2020.001.30018, and 2017.011.30188.
Can CVE-2021-28545 be exploited remotely?
Yes, CVE-2021-28545 can be exploited remotely by an unauthenticated attacker to manipulate data in a certified PDF.
Is there a workaround for CVE-2021-28545?
No specific workaround is provided for CVE-2021-28545; it is essential to apply the available updates to mitigate the risk.