CVE-2021-39841: Adobe Acrobat Pro DC DocMedia Type Confusion Remote Code Execution Vulnerability
Acrobat Reader DC versions 2021.005.20060 (and earlier), 2020.004.30006 (and earlier) and 2017.011.30199 (and earlier) are affected by a Type Confusion vulnerability. An attacker could leverage this vulnerability to execute arbitrary code in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Adobe Acrobat Reader DCto a version that resolves this vulnerability.Fixed in 2021.005.20060 - Upgrade
Upgrade
Adobe Acrobat Reader DCto a version that resolves this vulnerability.Fixed in 2020.004.30006 - Upgrade
Upgrade
Adobe Acrobat Reader DCto a version that resolves this vulnerability.Fixed in 2017.011.30199
Event History
Frequently Asked Questions
What is the severity of CVE-2021-39841?
CVE-2021-39841 has a critical severity rating as it allows attackers to execute arbitrary code in the context of the current user.
How do I fix CVE-2021-39841?
To mitigate CVE-2021-39841, update Adobe Acrobat Reader DC or Adobe Acrobat DC to the latest version released after the vulnerability was disclosed.
Which versions of Adobe Acrobat Reader are affected by CVE-2021-39841?
CVE-2021-39841 affects Adobe Acrobat Reader DC versions 2021.005.20060 and earlier, 2020.004.30006 and earlier, and 2017.011.30199 and earlier.
Can CVE-2021-39841 be exploited remotely?
Yes, CVE-2021-39841 can be exploited remotely, allowing attackers to execute malicious code without physical access to the device.
What type of vulnerability is CVE-2021-39841?
CVE-2021-39841 is classified as a Type Confusion vulnerability, which can lead to arbitrary code execution.