CVE-2021-21017
KEVmassHeap-Based Buffer Overflow in Adobe Acrobat and Reader Allows RCE via Malicious PDF
CISA: Adobe Acrobat and Reader Heap-based Buffer Overflow Vulnerability
CVE-2021-21017 is a heap-based buffer overflow (out-of-bounds write, CWE-122/CWE-787) in Adobe Acrobat and Reader DC that corrupts memory when a specially crafted PDF is processed. Exploitation requires user interaction: a victim must open the malicious PDF file, after which an unauthenticated, network-based attacker can execute arbitrary code in the context of the current user. Successful exploitation effectively gives the attacker the privileges of the victim user on the endpoint, including the ability to run programs and read or modify data. Users running Acrobat Reader DC or Acrobat DC at or below versions 2020.013.20074, 2020.001.30018, or 2017.011.30188 on the Continuous, Classic 2020, and Classic 2017 tracks are affected. The bug was addressed in Adobe's February 2021 updates but has been exploited in the wild - it was added to the CISA KEV catalog on 2021-11-03 - and EPSS assigns an 86.3% probability of exploitation within 30 days (100th percentile).
What to do: Upgrade all Acrobat and Reader installations to Adobe's February 2021 patched releases or later, per the vendor's instructions, as required by CISA KEV (added 2021-11-03). Inventory endpoints running Continuous, Classic 2020, or Classic 2017 builds at or below the listed versions and verify the running version after patching. Until patched, avoid opening PDFs from untrusted sources, since exploitation requires a victim to open a malicious file.
| Adobe Acrobat Reader DC | 2020.013.20074 and earlier (Continuous); 2020.001.30018 and earlier (Classic 2020); 2017.011.30188 and earlier (Classic 2017) |
| Adobe Acrobat DC | 2020.013.20074 and earlier (Continuous); 2020.001.30018 and earlier (Classic 2020); 2017.011.30188 and earlier (Classic 2017) |
| Adobe Acrobat | 2020.013.20074 and earlier; 2020.001.30018 and earlier; 2017.011.30188 and earlier |
| Adobe Acrobat Reader | 2020.013.20074 and earlier; 2020.001.30018 and earlier; 2017.011.30188 and earlier |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
Acrobat Reader DC versions versions 2020.013.20074 (and earlier), 2020.001.30018 (and earlier) and 2017.011.30188 (and earlier) are affected by a heap-based buffer overflow vulnerability. An unauthenticated attacker could leverage this vulnerability to achieve arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
- Affected
- Adobe Acrobat and Reader
- Required action
- Apply updates per vendor instructions.
- Due date
- Ransomware use
- Unknown
- Vendors
- adobe
- Products
- acrobat, acrobat dc, acrobat reader, acrobat reader dc
- Weakness
- CWE-122, CWE-787
- Vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H