CVE-2021-44706: Adobe Acrobat Reader Collab.registerReview Use-After-Free Remote Execution Vulnerability
Acrobat Reader DC version 21.007.20099 (and earlier), 20.004.30017 (and earlier) and 17.011.30204 (and earlier) are affected by a use-after-free vulnerability in the processing of Format event actions that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2021-44706.
What software versions are affected by this vulnerability?
Acrobat Reader DC versions 21.007.20099 and earlier, 20.004.30017 and earlier, and 17.011.30204 and earlier are affected.
What is the severity of CVE-2021-44706?
The severity of CVE-2021-44706 is critical with a CVSS score of 7.8.
What is the impact of this vulnerability?
This vulnerability could result in arbitrary code execution in the context of the current user.
Is there a fix available for this vulnerability?
Yes, Adobe has released a security update to address this vulnerability. Please refer to the official Adobe security advisory for more information.