CVE-2021-21017

HIGH KEV

Adobe Acrobat < 17.011.30188 - Out-of-Bounds Write

Title source: rule

Description

Acrobat Reader DC versions versions 2020.013.20074 (and earlier), 2020.001.30018 (and earlier) and 2017.011.30188 (and earlier) are affected by a heap-based buffer overflow vulnerability. An unauthenticated attacker could leverage this vulnerability to achieve arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

Exploits (2)

nomisec WORKING POC 43 stars
by ZeusBox · poc
https://github.com/ZeusBox/CVE-2021-21017
nomisec WORKING POC
by tzwlhack · client-side
https://github.com/tzwlhack/CVE-2021-21017

Scores

CVSS v3 8.8
EPSS 0.9020
EPSS Percentile 99.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Details

CISA KEV 2021-11-03
VulnCheck KEV 2021-02-09
InTheWild.io 2021-02-09
ENISA EUVD EUVD-2021-8423
CWE
CWE-122 CWE-787
Status published
Products (4)
adobe/acrobat 17.0 - 17.011.30188
adobe/acrobat_dc < 20.013.20074
adobe/acrobat_reader 17.0 - 17.011.30188
adobe/acrobat_reader_dc < 20.013.20074
Published Feb 11, 2021
KEV Added Nov 03, 2021
Tracked Since Feb 18, 2026