cbcvebase.
CVE-2021-35982
published 2021-09-29

CVE-2021-35982: Acrobat Reader DC versions 2021.005.20060 (and earlier), 2020.004.30006 (and earlier) and 2017.011.30199 (and earlier) are affected by an Uncontrolled Search…

high7.3CVSS 3.1
AVLACLPRLUIRSUCHIHAH
Acrobat Reader DC versions 2021.005.20060 (and earlier), 2020.004.30006 (and earlier) and 2017.011.30199 (and earlier) are affected by an Uncontrolled Search Path Element vulnerability. A local attacker with non-administrative privileges can plant a malicious DLL to achieve arbitrary code execution in the context of the current user via DLL hijacking. Exploitation of this issue requires user interaction.

Affected

8 ranges
VendorProductVersion rangeFixed in
adobeacrobat_dc17.011.30158 – 17.011.30199
adobeacrobat_dc20.004.30005 – 20.004.30006
adobeacrobat_dc20.006.20034 – 21.005.20060
adobeacrobat_dc20.006.20034 – 21.005.20058
adobeacrobat_readerunspecified – 2020.004.30006
adobeacrobat_reader_dc17.011.30158 – 17.011.30199
adobeacrobat_reader_dc20.004.30005 – 20.004.30006
adobeacrobat_reader_dc20.006.20034 – 21.005.20060