Aller au contenu
Appaloosa Scout
HIGH 8.8 KEV

CVE-2021-28550

Acrobat Reader DC versions versions 2021.001.20150 (and earlier), 2020.001.30020 (and earlier) and 2017.011.30194 (and earlier) are affected by a Use After Free vulnerability. An unauthenticated attacker could leverage this vulnerability to achieve arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

CVSS v3 CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

CISA Known Exploited Vulnerability

Ajouté au KEV
2021-11-03
Deadline remédiation
2021-11-17
Action requise
Apply updates per vendor instructions.
Ransomware
Non

Apps mobiles affectées

Configurations CPE vulnérables

Vendor Produit Plateforme Versions CPE 2.3 URI
adobe acrobat_reader Android ≥17.011.30059 ≤17.011.30194 cpe:2.3:a:adobe:acrobat_reader:*:*:*:*:classic:*:*:*
adobe acrobat_reader iOS ≥17.011.30059 ≤17.011.30194 cpe:2.3:a:adobe:acrobat_reader:*:*:*:*:classic:*:*:*
adobe acrobat_reader Android ≥20.001.30005 ≤20.001.30020 cpe:2.3:a:adobe:acrobat_reader:*:*:*:*:classic:*:*:*
adobe acrobat_reader iOS ≥20.001.30005 ≤20.001.30020 cpe:2.3:a:adobe:acrobat_reader:*:*:*:*:classic:*:*:*
Voir sur NVD ↗ Catalogue CISA KEV ↗