First published: Fri Aug 20 2021(Updated: )
Acrobat Reader DC versions 2021.005.20054 (and earlier), 2020.004.30005 (and earlier) and 2017.011.30197 (and earlier) are affected by a Null pointer dereference vulnerability. An unauthenticated attacker could leverage this vulnerability to achieve an application denial-of-service in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Credit: psirt@adobe.com
Affected Software | Affected Version | How to fix |
---|---|---|
Adobe Acrobat Reader DC | >=15.008.20082<=21.005.20054 | |
Adobe Acrobat Reader DC | >=17.011.30059<=17.011.30197 | |
Adobe Acrobat Reader DC | >=20.001.30005<=20.004.30005 | |
Adobe Acrobat Reader | >=15.008.20082<=21.005.20054 | |
Adobe Acrobat Reader | >=17.011.30059<=17.011.30197 | |
Adobe Acrobat Reader | >=20.001.30005<=20.004.30005 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2021-35985 is rated as a high severity vulnerability due to its potential to cause a denial-of-service attack.
To fix CVE-2021-35985, update Adobe Acrobat Reader DC to version 21.005.20055 or later, or apply any available patches.
Adobe Acrobat Reader DC versions 21.005.20054 and earlier, as well as several earlier versions of Acrobat DC and Acrobat Reader DC are affected by CVE-2021-35985.
Yes, CVE-2021-35985 can potentially be exploited by an unauthenticated attacker, making it a significant risk for remote exploitation.
CVE-2021-35985 is a null pointer dereference vulnerability that can result in application denial of service.