CVE-2021-28554: high-severity vulnerability in Adobe Acrobat Reader
Adobe Acrobat Reader DC Path Parsing Out-Of-Bounds Read could lead to arbitrary code execution
Published · Updated
No sign of exploitation. No public exploitation artifact known so far.
Adobe Acrobat Reader DC has a flaw where it reads data beyond safe memory boundaries when parsing file paths. An attacker can craft a malicious PDF that, when opened, executes harmful code on your computer.
An out-of-bounds read vulnerability in path parsing allows an unauthenticated attacker to trigger arbitrary code execution within the user's context. Exploitation requires social engineering to convince a user to open a specially crafted PDF file; the vulnerability exists in Acrobat Reader DC versions 2021.001.20155 and earlier, 2020.001.30025 and earlier, and 2017.011.30196 and earlier.
In the same product, most dangerous first.