CVE-2021-21017
HIGH KEVAdobe Acrobat and Acrobat Reader DC < 20.013.20074 and < 17.011.30188 - Unauthenticated Heap-based Buffer Overflow
Title source: llmExploitation Summary
CVE-2021-21017 is actively exploited and listed in the CISA Known Exploited Vulnerabilities (KEV) catalog, added November 3, 2021. EIP tracks 2 public exploits from researchers including ZeusBox, tzwlhack.
AI-analyzed exploit summary The repository contains a functional exploit PoC for CVE-2021-21017, a type confusion vulnerability in Adobe Reader's IA32 plugin. The exploit leverages a UTF-16BE string handling bug to achieve out-of-bounds read and heap overflow, potentially leading to arbitrary code execution.
Description
Acrobat Reader DC versions versions 2020.013.20074 (and earlier), 2020.001.30018 (and earlier) and 2017.011.30188 (and earlier) are affected by a heap-based buffer overflow vulnerability. An unauthenticated attacker could leverage this vulnerability to achieve arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Exploits (2)
The repository contains a functional exploit PoC for CVE-2021-21017, a type confusion vulnerability in Adobe Reader's IA32 plugin. The exploit leverages a UTF-16BE string handling bug to achieve out-of-bounds read and heap overflow, potentially leading to arbitrary code execution.
The repository contains a functional exploit PoC for CVE-2021-21017, a type confusion vulnerability in Adobe Reader's IA32 plugin (ver. 2020.013.20074). The exploit leverages a UTF-16BE string handling bug to achieve out-of-bounds read and heap overflow, potentially leading to arbitrary code execution.
References (2)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H