CVE-2021-28559: Adobe Acrobat Reader privacy violation vulnerability could lead to privilege escalation
Acrobat Reader DC versions versions 2021.001.20150 (and earlier), 2020.001.30020 (and earlier) and 2017.011.30194 (and earlier) are affected by an Information Exposure vulnerability. An unauthenticated attacker could leverage this vulnerability to get access to restricted data stored within global variables and objects.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2021-28559?
CVE-2021-28559 has been classified as a medium severity vulnerability.
How do I fix CVE-2021-28559?
To fix CVE-2021-28559, users should update Adobe Acrobat Reader DC to the latest version that addresses this vulnerability.
What versions of Adobe Acrobat are affected by CVE-2021-28559?
CVE-2021-28559 affects Adobe Acrobat Reader DC versions up to 21.001.20150, as well as earlier versions of Adobe Acrobat DC and Acrobat Reader.
Can unprivileged users exploit CVE-2021-28559?
Yes, an unauthenticated attacker can exploit CVE-2021-28559 to access restricted data.
What type of vulnerability is CVE-2021-28559?
CVE-2021-28559 is categorized as an Information Exposure vulnerability.