Aller au contenu
Appaloosa Scout
HIGH 8.8 KEV

CVE-2021-21017

Acrobat Reader DC versions versions 2020.013.20074 (and earlier), 2020.001.30018 (and earlier) and 2017.011.30188 (and earlier) are affected by a heap-based buffer overflow vulnerability. An unauthenticated attacker could leverage this vulnerability to achieve arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

CVSS v3 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

CISA Known Exploited Vulnerability

Ajouté au KEV
2021-11-03
Deadline remédiation
2021-11-17
Action requise
Apply updates per vendor instructions.
Ransomware
Non

Apps mobiles affectées

Configurations CPE vulnérables

Vendor Produit Plateforme Versions CPE 2.3 URI
adobe acrobat_reader Android ≥17.0 ≤17.011.30188 cpe:2.3:a:adobe:acrobat_reader:*:*:*:*:classic:*:*:*
adobe acrobat_reader iOS ≥17.0 ≤17.011.30188 cpe:2.3:a:adobe:acrobat_reader:*:*:*:*:classic:*:*:*
adobe acrobat_reader Android ≥20.0 ≤20.001.300183 cpe:2.3:a:adobe:acrobat_reader:*:*:*:*:classic:*:*:*
adobe acrobat_reader iOS ≥20.0 ≤20.001.300183 cpe:2.3:a:adobe:acrobat_reader:*:*:*:*:classic:*:*:*
Voir sur NVD ↗ Catalogue CISA KEV ↗