PT-2021-6844 · Adobe · Acrobat 2017+5

Published

2021-07-13

·

Updated

2021-09-01

·

CVE-2021-35987

CVSS v2.0

5.0

Medium

VectorAV:N/AC:L/Au:N/C:P/I:N/A:N
Name of the Vulnerable Software and Affected Versions Adobe Acrobat versions prior to 2021.005.20054 Adobe Acrobat Reader versions prior to 2021.005.20054 Adobe Acrobat 2017 versions prior to 2017.011.30197 Adobe Acrobat Reader 2017 versions prior to 2017.011.30197 Adobe Acrobat 2020 versions prior to 2020.004.30005 Adobe Acrobat Reader 2020 versions prior to 2020.004.30005
Description The issue is related to an out-of-bounds read vulnerability that can allow an unauthenticated attacker to disclose arbitrary memory information in the context of the current user. This can be achieved by exploiting the vulnerability using a specially crafted PDF file, which requires user interaction, such as opening a malicious file.
Recommendations For Adobe Acrobat versions prior to 2021.005.20054, update to version 2021.005.20054 or later. For Adobe Acrobat Reader versions prior to 2021.005.20054, update to version 2021.005.20054 or later. For Adobe Acrobat 2017 versions prior to 2017.011.30197, update to version 2017.011.30197 or later. For Adobe Acrobat Reader 2017 versions prior to 2017.011.30197, update to version 2017.011.30197 or later. For Adobe Acrobat 2020 versions prior to 2020.004.30005, update to version 2020.004.30005 or later. For Adobe Acrobat Reader 2020 versions prior to 2020.004.30005, update to version 2020.004.30005 or later.

Fix

Out of bounds Read

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2022-02290
CVE-2021-35987

Affected Products

Acrobat
Acrobat 2017
Acrobat 2020
Acrobat Reader
Acrobat Reader 2017
Acrobat Reader 2020