CVE-2021-39851: Adobe Acrobat Reader DC Null Pointer Dereference Could Lead To Application Denial-of-Service
Acrobat Reader DC versions 2021.005.20060 (and earlier), 2020.004.30006 (and earlier) and 2017.011.30199 (and earlier) are affected by a Null pointer dereference vulnerability. An unauthenticated attacker could leverage this vulnerability to achieve an application denial-of-service in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2021-39851?
The severity of CVE-2021-39851 is classified as medium due to its potential to cause denial-of-service.
How do I fix CVE-2021-39851?
To fix CVE-2021-39851, update Adobe Acrobat Reader DC to the latest version that is not vulnerable.
Which versions of Adobe Acrobat are affected by CVE-2021-39851?
Affected versions include Acrobat Reader DC versions up to 21.005.20060, as well as earlier versions of 2020 and 2017.
Can CVE-2021-39851 be exploited remotely?
Yes, CVE-2021-39851 can be exploited remotely by an unauthenticated attacker.
What type of vulnerability is CVE-2021-39851?
CVE-2021-39851 is a Null pointer dereference vulnerability.