CVE-2021-39840: Adobe Acrobat Reader DC AcroForm Field Use-After-Free Remote Code Execution Vulnerability
Acrobat Reader DC versions 2021.005.20060 (and earlier), 2020.004.30006 (and earlier) and 2017.011.30199 (and earlier) are affected by a use-after-free vulnerability when processing AcroForms that could result in arbitrary code execution in the context of the current user. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2021-39840?
CVE-2021-39840 has a critical severity rating due to the potential for arbitrary code execution.
How do I fix CVE-2021-39840?
To fix CVE-2021-39840, update Adobe Acrobat Reader or Adobe Acrobat DC to the latest version provided by Adobe.
What versions are affected by CVE-2021-39840?
CVE-2021-39840 affects Acrobat Reader DC versions 2021.005.20060 and earlier, 2020.004.30006 and earlier, and 2017.011.30199 and earlier.
What type of vulnerability is CVE-2021-39840?
CVE-2021-39840 is classified as a use-after-free vulnerability.
Can CVE-2021-39840 allow remote code execution?
Yes, CVE-2021-39840 can potentially allow remote code execution if exploited.