PT-2021-6636 · Adobe+1 · Acrobat Reader+3
Published
2021-09-14
·
Updated
2022-02-05
·
CVE-2021-39855
CVSS v2.0
7.8
High
| Vector | AV:N/AC:L/Au:N/C:C/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Acrobat Reader DC ActiveX Control versions 2021.005.20060 and earlier
Acrobat Reader DC ActiveX Control versions 2020.004.30006 and earlier
Acrobat Reader DC ActiveX Control versions 2017.011.30199 and earlier
Adobe Acrobat 2017 and earlier
Adobe Acrobat Reader 2017 and earlier
Adobe Acrobat 2020 and earlier
Adobe Acrobat Reader 2020 and earlier
Description
The issue is related to an Information Disclosure vulnerability that could allow an unauthenticated attacker to obtain NTLMv2 credentials. Exploitation requires user interaction, such as opening a maliciously crafted Microsoft Office file or visiting an attacker-controlled web page. This vulnerability may also allow attackers to read arbitrary files from the file system.
Recommendations
For Acrobat Reader DC ActiveX Control versions 2021.005.20060 and earlier, update to a version later than 2021.005.20060 to resolve the issue.
For Acrobat Reader DC ActiveX Control versions 2020.004.30006 and earlier, update to a version later than 2020.004.30006 to resolve the issue.
For Acrobat Reader DC ActiveX Control versions 2017.011.30199 and earlier, update to a version later than 2017.011.30199 to resolve the issue.
For Adobe Acrobat 2017 and earlier, Adobe Acrobat Reader 2017 and earlier, Adobe Acrobat 2020 and earlier, Adobe Acrobat Reader 2020 and earlier, consider disabling the ability to open maliciously crafted Microsoft Office files or restricting access to attacker-controlled web pages until a patch is available.
Fix
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Acrobat Reader Dc Activex Control
Acrobat
Acrobat Reader
Office