CVE-2021-44714
Adobe Acrobat Reader Missing Custom Protocols in Warning Message Prompts
In short
Adobe Acrobat Reader fails to warn users about custom protocols in PDFs, allowing attackers to trick users into allowing potentially harmful actions. The warning dialog is incomplete, making it easier to bypass security checks through user deception.
Technical detail
Acrobat Reader DC versions 21.007.20099 and earlier lack custom protocol warnings in security prompts (CWE-657: Violation of Secure Design Principles), enabling attackers to craft malicious PDFs that mislead users into granting permissions. Exploitation requires user interaction (clicking 'allow' on the incomplete warning), but the omission of protocol information in the dialog weakens the intended security barrier.
Summary generated and translated by AI from the official description.
Acrobat Reader DC version 21.007.20099 (and earlier), 20.004.30017 (and earlier) and 17.011.30204 (and earlier) are affected by a Violation of Secure Design Principles that could lead to a Security feature bypass. Acrobat Reader DC displays a warning message when a user clicks on a PDF file, which could be used by an attacker to mislead the user. In affected versions, this warning message does not include custom protocols when used by the sender. User interaction is required to abuse this vulnerability as they would need to click 'allow' on the warning message of a malicious file.
CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:L/I:N/A:N
Affected products
Adobe · Acrobat ReaderWant to know if your infrastructure is exposed to this?
Talk to TrueHacking →