CVE-2021-28562
published 2021-06-28CVE-2021-28562: Acrobat Reader DC versions versions 2021.001.20150 (and earlier), 2020.001.30020 (and earlier) and 2017.011.30194 (and earlier) are affected by a Use After…
PriorityP354high8.8CVSS 3.1
AVNACLPRNUIRSUCHIHAH
EPSS
5.12%
91.5th percentile
Acrobat Reader DC versions versions 2021.001.20150 (and earlier), 2020.001.30020 (and earlier) and 2017.011.30194 (and earlier) are affected by a Use After Free vulnerability when executing search queries through Javascript. An unauthenticated attacker could leverage this vulnerability to achieve arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Affected
3 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| adobe | acrobat_dc | 15.008.20082 – 21.001.20150 | — |
| adobe | acrobat_reader | unspecified – 2020.001.30020 | — |
| adobe | acrobat_reader_dc | 15.008.20082 – 21.001.20150 | — |
CVSS provenance
nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.06.8MEDIUMAV:N/AC:M/Au:N/C:P/I:P/A:P
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
No detection rules found.
No public exploits indexed.
Talos
Vulnerability Spotlight: Code execution vulnerability in Adobe Acrobat Reader
blogs_talos·2021-05-11·CVSS 8.8
CVE-2021-28562 [HIGH] Vulnerability Spotlight: Code execution vulnerability in Adobe Acrobat Reader
Aleksandar Nikolic of Cisco Talos discovered this vulnerability. Blog by Jon Munshaw.
Cisco Talos recently discovered an arbitrary code execution vulnerability in Adobe Acrobat Reader.
Adobe Acrobat Reader is one of the most popular and feature-rich PDF readers on the market. The software supports JavaScript so it can process interactive forms.
TALOS-2021-1233 (CVE-2021-28562) specifically exploits queries through JavaScript in a way that could allow an attacker to execute code on the targeted machine. An attacker needs to trick a user into opening a specially crafted, malicious PDF to exploit this vulnerability.
Cisco Talos worked with Adobe to ensure that that this issue is resolved and an update is available for affected customers, all in adherence to Cisco’s vulnerability disclosur
Qualys
Microsoft & Adobe Patch Tuesday (May 2021) – Qualys covers 85 Vulnerabilities, 26 Critical
blogs_qualys·2021-05-11·CVSS 9.9
CVE-2021-31181 [CRITICAL] Microsoft & Adobe Patch Tuesday (May 2021) – Qualys covers 85 Vulnerabilities, 26 Critical
## Microsoft Patch Tuesday – May 2021
Microsoft patched 55 CVEs in their May 2021 Patch Tuesday release, of which 4 are rated as critical severity. Three 0-day vulnerability patches were included in the release. As of this publication date, none have been exploited.
Qualys released 12 QIDs on the same day, providing vulnerability detection and patch management coverage (where applicable) for all 55 CVEs and the related KBs.
## Critical Microsoft vulnerabilities patched:
CVE-2021-31181 – SharePoint Remote Code Execution Vulnerability
Microsoft released patches addressing a critical RCE vulnerability in SharePoint (CVE-2021-31181). This CVE has a high likelihood of exploitability and is assigned a CVSSv3 base score of 8.8 by the vendor.
CVE-2021-31166 – HTTP Protocol Stack Remote Code
Talos
Vulnerability Spotlight: Code execution vulnerability in Adobe Acrobat Reader
blogs_talos·2021-05-11·CVSS 8.8
CVE-2021-28562 [HIGH] Vulnerability Spotlight: Code execution vulnerability in Adobe Acrobat Reader
## Vulnerability Spotlight: Code execution vulnerability in Adobe Acrobat Reader
Aleksandar Nikolic of Cisco Talos discovered this vulnerability. Blog by Jon Munshaw.
Cisco Talos recently discovered an arbitrary code execution vulnerability in Adobe Acrobat Reader.
Adobe Acrobat Reader is one of the most popular and feature-rich PDF readers on the market. The software supports JavaScript so it can process interactive forms.
TALOS-2021-1233 (CVE-2021-28562) specifically exploits queries through JavaScript in a way that could allow an attacker to execute code on the targeted machine. An attacker needs to trick a user into opening a specially crafted, malicious PDF to exploit this vulnerability.
Cisco Talos worked with Adobe to ensure that that this issue is resolved and an update is ava
2021-06-28
Published