PT-2021-4443 · Adobe · Acrobat Reader+1

Published

2021-10-12

·

Updated

2025-04-24

·

CVE-2021-40730

CVSS v2.0

4.3

Medium

VectorAV:N/AC:M/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions Adobe Acrobat Reader DC versions 21.007.20095 and earlier, 21.007.20096 and earlier, 20.004.30015 and earlier, 17.011.30202 and earlier Adobe Acrobat 2017 and earlier Adobe Acrobat Reader 2017 and earlier Adobe Acrobat 2020 and earlier Adobe Acrobat Reader 2020 and earlier
Description The issue is related to a use-after-free flaw that allows a remote attacker to disclose sensitive information on affected installations. This can be exploited when a user visits a malicious page or opens a malicious file, with the specific flaw existing within the parsing of JPG2000 images. The vulnerability may also allow attackers to escalate privileges.
Recommendations For Adobe Acrobat Reader DC versions 21.007.20095 and earlier, 21.007.20096 and earlier, 20.004.30015 and earlier, 17.011.30202 and earlier, update to a version later than the specified versions to resolve the issue. For Adobe Acrobat 2017 and earlier, Adobe Acrobat Reader 2017 and earlier, Adobe Acrobat 2020 and earlier, Adobe Acrobat Reader 2020 and earlier, consider disabling the JPG2000 image parsing functionality as a temporary workaround until a patch is available. Restrict access to malicious pages and files to minimize the risk of exploitation.

Fix

Use After Free

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2021-05073
CVE-2021-40730
ZDI-21-1162

Affected Products

Acrobat
Acrobat Reader