CVE-2021-44739Sensitive Information Exposure in Adobe Acrobat Reader

Severity
4.3MEDIUMNVD
EPSS
1.7%
top 17.55%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJan 14
Latest updateJan 15

Description

Acrobat Reader DC ActiveX Control versions 21.007.20099 (and earlier), 20.004.30017 (and earlier) and 17.011.30204 (and earlier) are affected by an Information Disclosure vulnerability. An unauthenticated attacker could leverage this vulnerability to obtain NTLMv2 credentials. Exploitation of this issue requires user interaction in that a victim must open a maliciously crafted Microsoft Office file, or visit an attacker controlled web page.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:NExploitability: 2.8 | Impact: 1.4

Affected Packages5 packages

CVEListV5adobe/acrobat_readerunspecified21.007.20099+3
NVDadobe/acrobat_reader20.001.3000520.004.30017+1
NVDadobe/acrobat_reader_dc21.001.2014921.007.20099
NVDadobe/acrobat20.001.3000520.004.30017+1
NVDadobe/acrobat_dc21.001.2014921.007.20099

Patches

🔴Vulnerability Details

2
GHSA
GHSA-2q59-h5qr-8vqm: Acrobat Reader DC ActiveX Control versions 212022-01-15
CVEList
Adobe Acrobat Reader DC add-on (AxAcroPDFLib.AxAcroPDF) src NTLMv2 SSO Auth leak vulnerability2022-01-14

🕵️Threat Intelligence

1
Zscaler
Zscaler protects against 25 Adobe vulnerability | 01-11-2022
CVE-2021-44739 — Sensitive Information Exposure | cvebase