CVE-2021-39860: Adobe Acrobat Reader DC Search Plugin Null Pointer Dereference
Acrobat Pro DC versions 2021.005.20060 (and earlier), 2020.004.30006 (and earlier) and 2017.011.30199 (and earlier) are affected by a Null pointer dereference vulnerability. An unauthenticated attacker could leverage this vulnerability to disclose sensitive user memory. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2021-39860?
CVE-2021-39860 is a vulnerability in Acrobat Pro DC versions 2021.005.20060 (and earlier), 2020.004.30006 (and earlier), and 2017.011.30199 (and earlier) that allows an unauthenticated attacker to disclose sensitive user memory.
How severe is CVE-2021-39860?
CVE-2021-39860 has a severity level of medium, with a CVSS score of 5.5.
Which software versions are affected by CVE-2021-39860?
Acrobat Pro DC versions 2021.005.20060 (and earlier), 2020.004.30006 (and earlier), and 2017.011.30199 (and earlier) are affected by CVE-2021-39860.
How can an attacker exploit CVE-2021-39860?
An unauthenticated attacker can exploit CVE-2021-39860 to disclose sensitive user memory.
Is Microsoft Windows vulnerable to CVE-2021-39860?
No, Microsoft Windows is not vulnerable to CVE-2021-39860.