ZeroHour

CVE-2021-28550

KEVmass

Use-After-Free RCE in Adobe Acrobat and Reader

CISA: Adobe Acrobat and Reader Use-After-Free Vulnerability

CVSS 3.1
8.8 high
EPSS
52%p99
Published
()
KEV added
AI analysis

CVE-2021-28550 is a use-after-free memory corruption flaw in Adobe Acrobat DC and Acrobat Reader DC that an unauthenticated attacker can trigger by getting a victim to open a malicious PDF file. Successful exploitation allows arbitrary code execution in the context of the current user, giving the attacker the privileges of that user on the affected machine. Anyone running Acrobat or Acrobat Reader DC at or below versions 2021.001.20150, 2020.001.30020, or 2017.011.30194 is affected. The flaw was exploited as a zero-day in targeted attacks — Microsoft reported it being chained with Windows zero-days by an Austrian company's operators — and it is listed in CISA's Known Exploited Vulnerabilities catalog as of November 3, 2021. CISA's required action is to apply vendor updates, and defenders should treat exploited, user-targeted PDF attacks as the primary risk.

What to do: Upgrade Acrobat and Acrobat Reader DC to versions later than 2021.001.20150, 2020.001.30020, and 2017.011.30194 on the respective tracks, per Adobe's May 2021 update and the CISA KEV required action. Until patched, avoid opening PDFs from untrusted sources and consider email-gateway filtering or sandboxing of PDF attachments. Check endpoint inventory for the affected version ranges and prioritize systems of users who handle unsolicited documents.

Affected
adobe Acrobat Reader DC2021.001.20150 and earlier; 2020.001.30020 and earlier; 2017.011.30194 and earlier
adobe Acrobat DC2021.001.20150 and earlier; 2020.001.30020 and earlier; 2017.011.30194 and earlier
adobe Acrobataffected per CISA (see DC ranges above)
adobe Acrobat Readeraffected per CISA (see DC ranges above)
Estimated exposure
masshundreds of millions of installations (Acrobat Reader is the world's most widely deployed PDF viewer) — Acrobat Reader is the de facto default PDF reader on Windows and Mac desktops with an installed base commonly reported in the hundreds of millions, so the vulnerable version ranges plausibly span a mass-scale population.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

Acrobat Reader DC versions versions 2021.001.20150 (and earlier), 2020.001.30020 (and earlier) and 2017.011.30194 (and earlier) are affected by a Use After Free vulnerability. An unauthenticated attacker could leverage this vulnerability to achieve arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

CISA Known Exploited Vulnerability
Affected
Adobe Acrobat and Reader
Required action
Apply updates per vendor instructions.
Due date
Ransomware use
Unknown
Vendors
adobe
Products
acrobat dc, acrobat reader dc, acrobat, acrobat reader
Weakness
CWE-416
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

In the news