PT-2021-6844 · Adobe · Acrobat 2017+5
Published
2021-07-13
·
Updated
2021-09-01
·
CVE-2021-35987
CVSS v2.0
5.0
Medium
| Vector | AV:N/AC:L/Au:N/C:P/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Adobe Acrobat versions prior to 2021.005.20054
Adobe Acrobat Reader versions prior to 2021.005.20054
Adobe Acrobat 2017 versions prior to 2017.011.30197
Adobe Acrobat Reader 2017 versions prior to 2017.011.30197
Adobe Acrobat 2020 versions prior to 2020.004.30005
Adobe Acrobat Reader 2020 versions prior to 2020.004.30005
Description
The issue is related to an out-of-bounds read vulnerability that can allow an unauthenticated attacker to disclose arbitrary memory information in the context of the current user. This can be achieved by exploiting the vulnerability using a specially crafted PDF file, which requires user interaction, such as opening a malicious file.
Recommendations
For Adobe Acrobat versions prior to 2021.005.20054, update to version 2021.005.20054 or later.
For Adobe Acrobat Reader versions prior to 2021.005.20054, update to version 2021.005.20054 or later.
For Adobe Acrobat 2017 versions prior to 2017.011.30197, update to version 2017.011.30197 or later.
For Adobe Acrobat Reader 2017 versions prior to 2017.011.30197, update to version 2017.011.30197 or later.
For Adobe Acrobat 2020 versions prior to 2020.004.30005, update to version 2020.004.30005 or later.
For Adobe Acrobat Reader 2020 versions prior to 2020.004.30005, update to version 2020.004.30005 or later.
Fix
Out of bounds Read
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Acrobat
Acrobat 2017
Acrobat 2020
Acrobat Reader
Acrobat Reader 2017
Acrobat Reader 2020