CVE-2021-28631: Adobe Acrobat Reader DC AcroForm Field Use-After-Free Remote Code Execution Vulnerability
Acrobat Reader DC versions versions 2021.001.20155 (and earlier), 2020.001.30025 (and earlier) and 2017.011.30196 (and earlier) are affected by an Use After Free vulnerability. An unauthenticated attacker could leverage this vulnerability to achieve arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2021-28631?
CVE-2021-28631 has been classified as a critical vulnerability due to its potential for arbitrary code execution.
How do I fix CVE-2021-28631?
To remediate CVE-2021-28631, users should update Adobe Acrobat Reader DC to the latest version available from Adobe.
Which versions of Adobe Acrobat Reader are affected by CVE-2021-28631?
CVE-2021-28631 affects Adobe Acrobat Reader DC versions up to 21.001.20155, 2020.001.30025, and 2017.011.30196.
Can CVE-2021-28631 lead to remote attacks?
Yes, CVE-2021-28631 can be exploited by unauthenticated attackers to execute arbitrary code remotely.
What platforms are impacted by CVE-2021-28631?
CVE-2021-28631 primarily impacts Adobe Acrobat Reader on both Windows and macOS platforms.