First published: Thu Sep 02 2021(Updated: )
Adobe Acrobat and Reader contains a use-after-free vulnerability that could allow an unauthenticated attacker to achieve code execution in the context of the current user.
Credit: psirt@adobe.com psirt@adobe.com
Affected Software | Affected Version | How to fix |
---|---|---|
Adobe Acrobat Reader Notification Manager | ||
All of | ||
Any of | ||
Adobe Acrobat Reader DC | >=15.008.20082<=21.001.20150 | |
Adobe Acrobat Reader | >=15.008.20082<=21.001.20150 | |
Microsoft Windows Operating System | ||
All of | ||
Any of | ||
Adobe Acrobat Reader | >=17.011.30059<=17.011.30194 | |
Adobe Acrobat Reader | >=20.001.30005<=20.001.30020 | |
Adobe Acrobat Reader Notification Manager | >=17.011.30059<=17.011.30194 | |
Adobe Acrobat Reader Notification Manager | >=20.001.30005<=20.001.30020 | |
Any of | ||
macOS | ||
Microsoft Windows Operating System | ||
All of | ||
Any of | ||
Adobe Acrobat Reader DC | >=15.008.20082<=21.001.20150 | |
Adobe Acrobat Reader | >=15.008.20082<=21.001.20150 | |
macOS | ||
Adobe Acrobat Reader DC | >=15.008.20082<=21.001.20150 | |
Adobe Acrobat Reader | >=15.008.20082<=21.001.20150 | |
Microsoft Windows Operating System | ||
Adobe Acrobat Reader | >=17.011.30059<=17.011.30194 | |
Adobe Acrobat Reader | >=20.001.30005<=20.001.30020 | |
Adobe Acrobat Reader Notification Manager | >=17.011.30059<=17.011.30194 | |
Adobe Acrobat Reader Notification Manager | >=20.001.30005<=20.001.30020 | |
macOS |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-28550 is a Use-After-Free vulnerability in Adobe Acrobat and Reader, which could allow an attacker to execute arbitrary code.
Acrobat Reader DC versions 2021.001.20150 (and earlier), 2020.001.30020 (and earlier), and 2017.011.30194 (and earlier) are affected by this vulnerability.
CVE-2021-28550 has a severity rating of 8.8, which is classified as critical.
An unauthenticated attacker could leverage this vulnerability to achieve arbitrary code execution in the context of the current user.
You can find more information about CVE-2021-28550 on the Adobe Security Bulletin APSB21-29.