CVE-2021-28634: Adobe Acrobat Reader AcrobatUtils.scpt Extension OS Command Injection Vulnerability
Acrobat Reader DC versions 2021.005.20054 (and earlier), 2020.004.30005 (and earlier) and 2017.011.30197 (and earlier) are affected by an Improper Neutralization of Special Elements used in an OS Command. An authenticated attacker could leverage this vulnerability to achieve arbitrary code execution on the host machine in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2021-28634?
CVE-2021-28634 is considered a critical vulnerability due to its potential for remote code execution.
How do I fix CVE-2021-28634?
To fix CVE-2021-28634, update Adobe Acrobat DC or Acrobat Reader DC to the latest version available.
Which versions are affected by CVE-2021-28634?
CVE-2021-28634 affects Acrobat Reader DC versions 2021.005.20054 and earlier, Acrobat DC versions 2020.004.30005 and earlier, and 2017.011.30197 and earlier.
Can CVE-2021-28634 be exploited without authentication?
No, an attacker must be authenticated to exploit CVE-2021-28634.
What type of vulnerability is CVE-2021-28634?
CVE-2021-28634 is classified as an Improper Neutralization of Special Elements used in an OS Command vulnerability.