← All CVEs

CVE-2021-21017

high · 8.8Actively exploited

On the CISA Known Exploited Vulnerabilities catalog

Apply updates per vendor instructions.

Added 2021-11-03Remediation due 2021-11-17

Acrobat Reader DC versions versions 2020.013.20074 (and earlier), 2020.001.30018 (and earlier) and 2017.011.30188 (and earlier) are affected by a heap-based buffer overflow vulnerability. An unauthenticated attacker could leverage this vulnerability to achieve arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

8.8
CVSS
86.3%
EPSS (exploit prob.)
100th
EPSS percentile
2021-02-11
Published

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Weaknesses

CWE-122CWE-787

Affected products

VendorProductAffected versions
adobeacrobat>= 17.0, <= 17.011.30188
adobeacrobat>= 20.0, <= 20.001.30018
adobeacrobat_dc<= 20.013.20074
adobeacrobat_reader>= 17.0, <= 17.011.30188
adobeacrobat_reader>= 20.0, <= 20.001.300183
adobeacrobat_reader_dc<= 20.013.20074
applemacosall versions
microsoftwindowsall versions

Check a specific version with /api/v1/cve/match.

References

Query this programmatically:

curl https://evil-db.io/api/v1/cve/CVE-2021-21017