⚠ Actively exploited
Added to CISA KEV on 2021-11-03. Federal agencies required to patch by 2021-11-17. Required action: Apply updates per vendor instructions..

CVE-2021-21017Heap-based Buffer Overflow in Adobe Acrobat Reader

Severity
8.8HIGHNVD
EPSS
90.2%
top 0.41%
CISA KEV
KEV
Added 2021-11-03
Due 2021-11-17
Exploit
Exploited in wild
Active exploitation observed
Timeline
PublishedFeb 11
KEV addedNov 3
KEV dueNov 17
Latest updateMay 24
CISA Required Action: Apply updates per vendor instructions.

Description

Acrobat Reader DC versions versions 2020.013.20074 (and earlier), 2020.001.30018 (and earlier) and 2017.011.30188 (and earlier) are affected by a heap-based buffer overflow vulnerability. An unauthenticated attacker could leverage this vulnerability to achieve arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:HExploitability: 2.8 | Impact: 5.9

Affected Packages5 packages

CVEListV5adobe/acrobat_readerunspecified2020.013.20074+3
NVDadobe/acrobat_reader17.017.011.30188+1
NVDadobe/acrobat_reader_dc20.013.20074
NVDadobe/acrobat17.017.011.30188+1
NVDadobe/acrobat_dc20.013.20074

🔴Vulnerability Details

3
GHSA
GHSA-r8q2-5jr4-57f7: Acrobat Reader DC versions versions 20202022-05-24
CVEList
Acrobat Reader DC Heap-based Buffer Overflow Vulnerability Could Lead To Arbitrary Code Execution2021-02-11
VulnCheck
Adobe Acrobat and Reader Heap-based Buffer Overflow Vulnerability2021

📋Vendor Advisories

1
CISA
Adobe Acrobat and Reader Heap-based Buffer Overflow Vulnerability2021-11-03

🕵️Threat Intelligence

8
Qualys
Managing CISA Known Exploited Vulnerabilities with Qualys VMDR | Qualys2022-02-23
Qualys
Qualys Response to CISA Alert: Binding Operational Directive 22-012021-11-09
Qualys
Qualys Response to CISA Alert: Binding Operational Directive 22-01 | Qualys2021-11-09
Securelist
IT threat evolution Q1 2021. Non-mobile statistics2021-05-31
Securelist
IT threat evolution Q1 2021. Non-mobile statistics2021-05-31
CVE-2021-21017 — Heap-based Buffer Overflow in Adobe | cvebase