First published: Tue May 11 2021(Updated: )
Acrobat Reader DC versions versions 2021.001.20150 (and earlier), 2020.001.30020 (and earlier) and 2017.011.30194 (and earlier) are affected by an Information Exposure vulnerability. An unauthenticated attacker could leverage this vulnerability to get access to restricted data stored within global variables and objects.
Credit: psirt@adobe.com
Affected Software | Affected Version | How to fix |
---|---|---|
Adobe Acrobat | >=15.008.20082<=21.001.20150 | |
Adobe Acrobat Reader | >=15.008.20082<=21.001.20150 | |
Microsoft Windows | ||
Adobe Acrobat Reader | >=17.011.30059<=17.011.30194 | |
Adobe Acrobat Reader | >=20.001.30005<=20.001.30020 | |
Adobe Acrobat Reader | >=17.011.30059<=17.011.30194 | |
Adobe Acrobat Reader | >=20.001.30005<=20.001.30020 | |
Apple iOS and macOS |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-28559 has been classified as a medium severity vulnerability.
To fix CVE-2021-28559, users should update Adobe Acrobat Reader DC to the latest version that addresses this vulnerability.
CVE-2021-28559 affects Adobe Acrobat Reader DC versions up to 21.001.20150, as well as earlier versions of Adobe Acrobat DC and Acrobat Reader.
Yes, an unauthenticated attacker can exploit CVE-2021-28559 to access restricted data.
CVE-2021-28559 is categorized as an Information Exposure vulnerability.