CVE-2021-21017: high-severity vulnerability in Adobe Acrobat Reader
Acrobat Reader DC Heap-based Buffer Overflow Vulnerability Could Lead To Arbitrary Code Execution
Published · Updated
Prioritize patching. It under exploitation confirmed by CISA and has a public proof of concept.
Apply updates per vendor instructions.
Acrobat Reader DC has a memory flaw that lets attackers run malicious code on your computer if you open a specially crafted PDF file. This is dangerous because it gives attackers full control over your system.
A heap-based buffer overflow in Acrobat Reader DC (versions 2020.013.20074 and earlier, 2020.001.30018 and earlier, 2017.011.30188 and earlier) allows unauthenticated attackers to execute arbitrary code with user privileges. The attack vector requires user interaction—opening a malicious PDF file—but once executed, it achieves code execution in the current user context.
The full analysis of this CVE is available in Portuguese →
In the same product, most dangerous first.