ZeroHour

CVE-2021-21017

KEVmass

Heap-Based Buffer Overflow in Adobe Acrobat and Reader Allows RCE via Malicious PDF

CISA: Adobe Acrobat and Reader Heap-based Buffer Overflow Vulnerability

CVSS 3.1
8.8 high
EPSS
86%p100
Published
()
KEV added
AI analysis

CVE-2021-21017 is a heap-based buffer overflow (out-of-bounds write, CWE-122/CWE-787) in Adobe Acrobat and Reader DC that corrupts memory when a specially crafted PDF is processed. Exploitation requires user interaction: a victim must open the malicious PDF file, after which an unauthenticated, network-based attacker can execute arbitrary code in the context of the current user. Successful exploitation effectively gives the attacker the privileges of the victim user on the endpoint, including the ability to run programs and read or modify data. Users running Acrobat Reader DC or Acrobat DC at or below versions 2020.013.20074, 2020.001.30018, or 2017.011.30188 on the Continuous, Classic 2020, and Classic 2017 tracks are affected. The bug was addressed in Adobe's February 2021 updates but has been exploited in the wild - it was added to the CISA KEV catalog on 2021-11-03 - and EPSS assigns an 86.3% probability of exploitation within 30 days (100th percentile).

What to do: Upgrade all Acrobat and Reader installations to Adobe's February 2021 patched releases or later, per the vendor's instructions, as required by CISA KEV (added 2021-11-03). Inventory endpoints running Continuous, Classic 2020, or Classic 2017 builds at or below the listed versions and verify the running version after patching. Until patched, avoid opening PDFs from untrusted sources, since exploitation requires a victim to open a malicious file.

Affected
Adobe Acrobat Reader DC2020.013.20074 and earlier (Continuous); 2020.001.30018 and earlier (Classic 2020); 2017.011.30188 and earlier (Classic 2017)
Adobe Acrobat DC2020.013.20074 and earlier (Continuous); 2020.001.30018 and earlier (Classic 2020); 2017.011.30188 and earlier (Classic 2017)
Adobe Acrobat2020.013.20074 and earlier; 2020.001.30018 and earlier; 2017.011.30188 and earlier
Adobe Acrobat Reader2020.013.20074 and earlier; 2020.001.30018 and earlier; 2017.011.30188 and earlier
Estimated exposure
masshundreds of millions of user installs worldwide (Reader is the dominant desktop PDF viewer) — Adobe Acrobat/Reader is the most widely deployed PDF reader on Windows and macOS with an installed base commonly cited in the hundreds of millions, so exposure is estimated from that market dominance rather than a specific scan count; the…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Acrobat Reader DC versions versions 2020.013.20074 (and earlier), 2020.001.30018 (and earlier) and 2017.011.30188 (and earlier) are affected by a heap-based buffer overflow vulnerability. An unauthenticated attacker could leverage this vulnerability to achieve arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

CISA Known Exploited Vulnerability
Affected
Adobe Acrobat and Reader
Required action
Apply updates per vendor instructions.
Due date
Ransomware use
Unknown
Vendors
adobe
Products
acrobat, acrobat dc, acrobat reader, acrobat reader dc
Weakness
CWE-122, CWE-787
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

In the news