CVE-2021-40729Out-of-bounds Read in Adobe Acrobat Reader

CWE-125Out-of-bounds Read5 documents4 sources
Severity
3.3LOWNVD
EPSS
0.7%
top 27.59%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedOct 15
Latest updateMay 24

Description

Adobe Acrobat Reader DC version 21.007.20095 (and earlier), 21.007.20096 (and earlier), 20.004.30015 (and earlier), and 17.011.30202 (and earlier) is affected by a out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious PDF file.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:NExploitability: 1.8 | Impact: 1.4

Affected Packages5 packages

CVEListV5adobe/acrobat_readerunspecified21.007.20095+3
NVDadobe/acrobat_reader20.001.3000520.004.30015+1
NVDadobe/acrobat_reader_dc15.008.2008221.007.20095+1
NVDadobe/acrobat20.001.3000520.004.30015+1
NVDadobe/acrobat_dc15.008.2008221.007.20095+1

🔴Vulnerability Details

2
GHSA
GHSA-h98h-qp56-wrjw: Adobe Acrobat Reader DC version 212022-05-24
CVEList
Adobe Acrobat Reader DC PDF Out-of-Bound Read Vulnerability Information Disclosure2021-10-15

🕵️Threat Intelligence

2
Zscaler
Acrobat Out-of-Bounds Read Vulnerability (CVE-2021-40729)2022-01-31
Zscaler
Zscaler protects against Adobe vulnerabilities | 10-12-2021
CVE-2021-40729 — Out-of-bounds Read in Adobe | cvebase