PT-2021-2304 · Adobe · Acrobat+1
Published
2021-02-09
·
Updated
2021-09-08
·
CVE-2021-21036
CVSS v3.1
7.8
High
| Vector | AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Adobe Acrobat versions prior to 2020.013.20074
Adobe Acrobat versions prior to 2020.001.30018
Adobe Acrobat versions prior to 2017.011.30188
Adobe Reader versions prior to 2020.013.20074
Adobe Reader versions prior to 2020.001.30018
Adobe Reader versions prior to 2017.011.30188
Description
The issue is related to an integer overflow vulnerability. It can be exploited by a remote attacker using a specially crafted PDF file, allowing them to execute arbitrary code in the context of the current user. Exploitation requires user interaction, such as opening a malicious file.
Recommendations
For Adobe Acrobat versions prior to 2020.013.20074, update to a version later than 2020.013.20074.
For Adobe Acrobat versions prior to 2020.001.30018, update to a version later than 2020.001.30018.
For Adobe Acrobat versions prior to 2017.011.30188, update to a version later than 2017.011.30188.
For Adobe Reader versions prior to 2020.013.20074, update to a version later than 2020.013.20074.
For Adobe Reader versions prior to 2020.001.30018, update to a version later than 2020.001.30018.
For Adobe Reader versions prior to 2017.011.30188, update to a version later than 2017.011.30188.
Fix
Integer Overflow
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Acrobat
Reader