CVE-2021-21017

HIGH KEV

Adobe Acrobat and Acrobat Reader DC < 20.013.20074 and < 17.011.30188 - Unauthenticated Heap-based Buffer Overflow

Title source: llm
STIX 2.1

Exploitation Summary

CVE-2021-21017 is actively exploited and listed in the CISA Known Exploited Vulnerabilities (KEV) catalog, added November 3, 2021. EIP tracks 2 public exploits from researchers including ZeusBox, tzwlhack.

AI-analyzed exploit summary The repository contains a functional exploit PoC for CVE-2021-21017, a type confusion vulnerability in Adobe Reader's IA32 plugin. The exploit leverages a UTF-16BE string handling bug to achieve out-of-bounds read and heap overflow, potentially leading to arbitrary code execution.

Description

Acrobat Reader DC versions versions 2020.013.20074 (and earlier), 2020.001.30018 (and earlier) and 2017.011.30188 (and earlier) are affected by a heap-based buffer overflow vulnerability. An unauthenticated attacker could leverage this vulnerability to achieve arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

Exploits (2)

nomisec WORKING POC 43 stars
by ZeusBox · poc
https://github.com/ZeusBox/CVE-2021-21017

The repository contains a functional exploit PoC for CVE-2021-21017, a type confusion vulnerability in Adobe Reader's IA32 plugin. The exploit leverages a UTF-16BE string handling bug to achieve out-of-bounds read and heap overflow, potentially leading to arbitrary code execution.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Complex
Reliability
Racy
Target: Adobe Reader (IA32 plugin, ver. 2020.013.20074)
No auth needed
Prerequisites: Victim must open a malicious PDF document · Adobe Reader with vulnerable IA32 plugin
devstral-2 · analyzed Feb 18, 2026 Full analysis →
nomisec WORKING POC
by tzwlhack · client-side
https://github.com/tzwlhack/CVE-2021-21017

The repository contains a functional exploit PoC for CVE-2021-21017, a type confusion vulnerability in Adobe Reader's IA32 plugin (ver. 2020.013.20074). The exploit leverages a UTF-16BE string handling bug to achieve out-of-bounds read and heap overflow, potentially leading to arbitrary code execution.

Classification
Working Poc 95%
Attack Type
Rce
Complexity
Complex
Reliability
Racy
Target: Adobe Reader (IA32 plugin, ver. 2020.013.20074)
No auth needed
Prerequisites: Victim must open a malicious PDF document · Adobe Reader with vulnerable IA32 plugin version
devstral-2 · analyzed Feb 18, 2026 Full analysis →

References (2)

Core 2

Scores

CVSS v3 8.8
EPSS 0.8627
EPSS Percentile 99.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation active
Automatable no
Technical Impact total

Details

CISA KEV 2021-11-03
VulnCheck KEV 2021-02-09
InTheWild.io 2021-02-09
ENISA EUVD EUVD-2021-8423
CWE
CWE-122 CWE-787
Status published
Products (4)
adobe/acrobat 17.0 - 17.011.30188
adobe/acrobat_dc < 20.013.20074
adobe/acrobat_reader 17.0 - 17.011.30188
adobe/acrobat_reader_dc < 20.013.20074
Published Feb 11, 2021
KEV Added Nov 03, 2021
Tracked Since Feb 18, 2026