CVE-2021-44713: Adobe Acrobat Reader DC Use After Free could lead to Application denial-of-service
Acrobat Reader DC version 21.007.20099 (and earlier), 20.004.30017 (and earlier) and 17.011.30204 (and earlier) are affected by a use-after-free vulnerability in the processing of Format event actions that could result in application denial of service. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2021-44713?
CVE-2021-44713 is considered a medium severity vulnerability due to its potential to cause application denial of service.
How do I fix CVE-2021-44713?
To fix CVE-2021-44713, users should update Adobe Acrobat Reader DC to version 21.007.20102 or later, 20.004.30018 or later, or 17.011.30205 or later.
What versions of Adobe Acrobat are affected by CVE-2021-44713?
CVE-2021-44713 affects Adobe Acrobat Reader DC versions 21.007.20099 and earlier, and 20.004.30017 and earlier, as well as Adobe Acrobat versions 17.011.30204 and earlier.
What causes the vulnerability CVE-2021-44713?
CVE-2021-44713 is caused by a use-after-free vulnerability in the processing of Format event actions.
Can CVE-2021-44713 lead to data loss?
While CVE-2021-44713 primarily causes denial of service, it could potentially lead to data loss if the application crashes unexpectedly.