PT-2021-6377 · Adobe · Adobe Acrobat Reader Document Cloud+3

Published

2021-07-13

·

Updated

2021-09-01

·

CVE-2021-35984

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Adobe Acrobat 2017 versions prior to the fixed version Adobe Acrobat 2020 versions prior to the fixed version Adobe Acrobat Document Cloud versions prior to the fixed version Adobe Acrobat Reader 2017 versions prior to the fixed version Adobe Acrobat Reader 2020 versions prior to the fixed version Adobe Acrobat Reader Document Cloud versions prior to the fixed version Acrobat Reader DC versions 2021.005.20054 and earlier Acrobat Reader DC versions 2020.004.30005 and earlier Acrobat Reader DC versions 2017.011.30197 and earlier
Description The issue is related to a null pointer dereference vulnerability in Adobe Acrobat and Reader. This vulnerability can be exploited by an authenticated attacker to achieve an application denial-of-service in the context of the current user. Exploitation of this issue does not require user interaction.
Recommendations For Adobe Acrobat 2017, update to a version that includes a fix for this issue. For Adobe Acrobat 2020, update to a version that includes a fix for this issue. For Adobe Acrobat Document Cloud, update to a version that includes a fix for this issue. For Adobe Acrobat Reader 2017, update to a version that includes a fix for this issue. For Adobe Acrobat Reader 2020, update to a version that includes a fix for this issue. For Adobe Acrobat Reader Document Cloud, update to a version that includes a fix for this issue. For Acrobat Reader DC versions 2021.005.20054 and earlier, update to a version that includes a fix for this issue. For Acrobat Reader DC versions 2020.004.30005 and earlier, update to a version that includes a fix for this issue. For Acrobat Reader DC versions 2017.011.30197 and earlier, update to a version that includes a fix for this issue.

Fix

DoS

NULL Pointer Dereference

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2022-01403
CVE-2021-35984

Affected Products

Acrobat Reader
Acrobat
Acrobat Document Cloud
Adobe Acrobat Reader Document Cloud