CVE-2021-28643: Adobe Acrobat Pro DC embedDocAsDataObject Type Confusion Information Disclosure Vulnerability
Acrobat Reader DC versions 2021.005.20054 (and earlier), 2020.004.30005 (and earlier) and 2017.011.30197 (and earlier) are affected by a Type Confusion vulnerability. An unauthenticated attacker could leverage this vulnerability to disclose sensitive memory information in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2021-28643?
CVE-2021-28643 is classified as a critical severity vulnerability due to its potential for disclosure of sensitive memory information.
How do I fix CVE-2021-28643?
To fix CVE-2021-28643, update Adobe Acrobat Reader DC to the latest version released after April 2021.
Which software versions are affected by CVE-2021-28643?
CVE-2021-28643 affects Adobe Acrobat Reader DC versions 2021.005.20054 and earlier, 2020.004.30005 and earlier, and 2017.011.30197 and earlier.
What type of vulnerability is CVE-2021-28643?
CVE-2021-28643 is a Type Confusion vulnerability.
Can CVE-2021-28643 be exploited by an authenticated attacker?
CVE-2021-28643 can be exploited by an unauthenticated attacker.