CVE-2021-21017KEV · OVERDUECWE-122

Acrobat Reader DC Heap-based Buffer Overflow Vulnerability Could Lead To Arbitrary Code Execution

High · published February 11, 2021

Patch now

Confirmed exploited, and the score agrees

CVSS calls it high at 8.8. It is confirmed in active exploitation. It sits in the 99.7th percentile for exploit probability.

1754
days past CISA
deadline
CVSS v3.1
8.8
EPSS
86%
Percentile
99.7
In the wild
Confirmed
What it is

🚨 A simple click could unleash chaos! A crafty attacker can exploit a heap-based buffer overflow in Acrobat Reader DC, turning an innocent file into a weapon of mass disruption. ⚡ Think of it like inviting a stranger into your home under the guise of delivering a package — once they’re in, they can rummage through your belongings and cause all sorts of trouble! 📦 If someone falls for this trick and opens a malicious file, the attacker could run arbitrary code as if they were the user. That means they could access private files, install malware, or even take control of the system. This kind of access can be absolutely devastating!

Put simply

Think of it like inviting a stranger into your home under the guise of delivering a package — once they’re in, they can rummage through your belongings and cause all sorts of trouble! 📦 This vulnerability allows an unauthenticated attacker to exploit a heap buffer overflow in specific versions of Acrobat Reader DC, enabling them to execute arbitrary code when the user opens a specially crafted file.

What to do

If someone falls for this trick and opens a malicious file, the attacker could run arbitrary code as if they were the user. That means they could access private files, install malware, or even take control of the system. This kind of access can be absolutely devastating! To protect yourself, update Acrobat Reader DC immediately to version 2020.013.20074 or later, or 2020.001.30018 or later, or 2017.011.30189 or later. Also, remind users to be cautious about opening unexpected files! 🛡️ You've got this! Follow these steps, and you’ll keep your systems safe and sound! 😊💪

The record
Technical detail
CVSS v3.1
8.8 · HIGH
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
CVSS v4.0
Not supplied
EPSS
0.86326 · 99.7th percentile
Weakness
CWE-122 · Heap-based Buffer Overflow
Published
2021-02-11T19:42Z
KEV added
2021-11-03 · due 2021-11-17
EPSS history
Timeline
  • 03 NOV 00:00Z
    Added to CISA KEV — remediate by Nov 17
    kev
  • 11 FEB 19:42Z
    Acrobat Reader DC Heap-based Buffer Overflow Vulnerability Could Lead To Arbitrary Code Execution
    cvelistv5