CVE-2021-28546: Acrobat Reader DC Missing Support for Integrity Check
Acrobat Reader DC versions versions 2020.013.20074 (and earlier), 2020.001.30018 (and earlier) and 2017.011.30188 (and earlier) are missing support for an integrity check. An unauthenticated attacker could leverage this vulnerability to modify content in a certified PDF without invalidating the certification. Exploitation of this issue requires user interaction in that a victim must open the tampered file.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2021-28546?
CVE-2021-28546 has been rated as important due to the potential impact on the integrity of PDF documents.
How do I fix CVE-2021-28546?
To mitigate CVE-2021-28546, update Adobe Acrobat Reader DC to the latest version available.
Which Adobe products are affected by CVE-2021-28546?
CVE-2021-28546 affects specific versions of Adobe Acrobat Reader DC, Adobe Acrobat, and Adobe Acrobat Reader.
Can an unauthenticated attacker exploit CVE-2021-28546?
Yes, an unauthenticated attacker can exploit CVE-2021-28546 to modify content in a certified PDF.
What does CVE-2021-28546 lack that exposes it to a vulnerability?
CVE-2021-28546 is missing support for an integrity check, allowing modifications without invalidating the document.