First published: Thu Sep 02 2021(Updated: )
Adobe Acrobat and Reader contains a use-after-free vulnerability that could allow an unauthenticated attacker to achieve code execution in the context of the current user.
Credit: psirt@adobe.com psirt@adobe.com
Affected Software | Affected Version | How to fix |
---|---|---|
Adobe Acrobat Dc | >=15.008.20082<=21.001.20150 | |
Adobe Acrobat Reader DC | >=15.008.20082<=21.001.20150 | |
Microsoft Windows | ||
Adobe Acrobat Reader | >=17.011.30059<=17.011.30194 | |
Adobe Acrobat Reader | >=20.001.30005<=20.001.30020 | |
Adobe Acrobat Reader | >=17.011.30059<=17.011.30194 | |
Adobe Acrobat Reader | >=20.001.30005<=20.001.30020 | |
Apple macOS | ||
All of | ||
Any of | ||
Adobe Acrobat Dc | >=15.008.20082<=21.001.20150 | |
Adobe Acrobat Reader DC | >=15.008.20082<=21.001.20150 | |
Microsoft Windows | ||
All of | ||
Any of | ||
Adobe Acrobat Reader | >=17.011.30059<=17.011.30194 | |
Adobe Acrobat Reader | >=20.001.30005<=20.001.30020 | |
Adobe Acrobat Reader | >=17.011.30059<=17.011.30194 | |
Adobe Acrobat Reader | >=20.001.30005<=20.001.30020 | |
Any of | ||
Apple macOS | ||
Microsoft Windows | ||
All of | ||
Any of | ||
Adobe Acrobat Dc | >=15.008.20082<=21.001.20150 | |
Adobe Acrobat Reader DC | >=15.008.20082<=21.001.20150 | |
Apple macOS | ||
Adobe Acrobat and Reader | ||
All of | ||
Any of | ||
>=15.008.20082<=21.001.20150 | ||
>=15.008.20082<=21.001.20150 | ||
All of | ||
Any of | ||
>=17.011.30059<=17.011.30194 | ||
>=20.001.30005<=20.001.30020 | ||
>=17.011.30059<=17.011.30194 | ||
>=20.001.30005<=20.001.30020 | ||
Any of | ||
All of | ||
Any of | ||
>=15.008.20082<=21.001.20150 | ||
>=15.008.20082<=21.001.20150 | ||
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-28550 is a Use-After-Free vulnerability in Adobe Acrobat and Reader, which could allow an attacker to execute arbitrary code.
Acrobat Reader DC versions 2021.001.20150 (and earlier), 2020.001.30020 (and earlier), and 2017.011.30194 (and earlier) are affected by this vulnerability.
CVE-2021-28550 has a severity rating of 8.8, which is classified as critical.
An unauthenticated attacker could leverage this vulnerability to achieve arbitrary code execution in the context of the current user.
You can find more information about CVE-2021-28550 on the Adobe Security Bulletin APSB21-29.