PT-2021-3328 · Adobe · Reader+1

Published

2021-05-11

·

Updated

2021-09-15

·

CVE-2021-28559

CVSS v3.1

5.3

Medium

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N
Name of the Vulnerable Software and Affected Versions Adobe Acrobat versions prior to 2021.001.20150 Adobe Acrobat versions prior to 2020.001.30020 Adobe Acrobat versions prior to 2017.011.30194 Adobe Reader versions prior to 2021.001.20150 Adobe Reader versions prior to 2020.001.30020 Adobe Reader versions prior to 2017.011.30194
Description The issue is related to information exposure and can be exploited by a remote attacker to elevate privileges and gain access to confidential information using a specially crafted PDF file. An unauthenticated attacker could leverage this vulnerability to get access to restricted data stored within global variables and objects.
Recommendations For Adobe Acrobat versions prior to 2021.001.20150, update to a version later than 2021.001.20150 to resolve the issue. For Adobe Acrobat versions prior to 2020.001.30020, update to a version later than 2020.001.30020 to resolve the issue. For Adobe Acrobat versions prior to 2017.011.30194, update to a version later than 2017.011.30194 to resolve the issue. For Adobe Reader versions prior to 2021.001.20150, update to a version later than 2021.001.20150 to resolve the issue. For Adobe Reader versions prior to 2020.001.30020, update to a version later than 2020.001.30020 to resolve the issue. For Adobe Reader versions prior to 2017.011.30194, update to a version later than 2017.011.30194 to resolve the issue.

Fix

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2021-03124
CVE-2021-28559

Affected Products

Acrobat
Reader