PT-2021-3328 · Adobe · Reader+1
Published
2021-05-11
·
Updated
2021-09-15
·
CVE-2021-28559
CVSS v3.1
5.3
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Adobe Acrobat versions prior to 2021.001.20150
Adobe Acrobat versions prior to 2020.001.30020
Adobe Acrobat versions prior to 2017.011.30194
Adobe Reader versions prior to 2021.001.20150
Adobe Reader versions prior to 2020.001.30020
Adobe Reader versions prior to 2017.011.30194
Description
The issue is related to information exposure and can be exploited by a remote attacker to elevate privileges and gain access to confidential information using a specially crafted PDF file. An unauthenticated attacker could leverage this vulnerability to get access to restricted data stored within global variables and objects.
Recommendations
For Adobe Acrobat versions prior to 2021.001.20150, update to a version later than 2021.001.20150 to resolve the issue.
For Adobe Acrobat versions prior to 2020.001.30020, update to a version later than 2020.001.30020 to resolve the issue.
For Adobe Acrobat versions prior to 2017.011.30194, update to a version later than 2017.011.30194 to resolve the issue.
For Adobe Reader versions prior to 2021.001.20150, update to a version later than 2021.001.20150 to resolve the issue.
For Adobe Reader versions prior to 2020.001.30020, update to a version later than 2020.001.30020 to resolve the issue.
For Adobe Reader versions prior to 2017.011.30194, update to a version later than 2017.011.30194 to resolve the issue.
Fix
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Acrobat
Reader