helpx.adobe.com
https://helpx.adobe.com/security/products/acrobat/apsb21-09.html CVE-2021-21017
HIGHCISA KEV
Acrobat Reader DC Heap-based Buffer Overflow Vulnerability Could Lead To Arbitrary Code Execution
Record summary
CVE-2021-21017 has a selected CVSS score of 8.8 (high); EIP currently links 1 repository PoC. CISA lists CVE-2021-21017 in KEV.
Description
Acrobat Reader DC versions versions 2020.013.20074 (and earlier), 2020.001.30018 (and earlier) and 2017.011.30188 (and earlier) are affected by a heap-based buffer overflow vulnerability. An unauthenticated attacker could leverage this vulnerability to achieve arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Description source: CVE List
Exploitation context
Known exploitation
- CISA KEV
- Listed · Nov 3, 2021 · CISA
- VulnCheck KEV
- Listed · Feb 9, 2021 · VulnCheck
- Reported exploitation
- Observed · VulnCheck
Available material
- Repository PoCs
- 1
CISA SSVC decision
ExploitationActive
AutomatableNo
Technical impactTotal
CISA Coordinator · SSVC 2.0.3 · Evaluated Feb 4, 2025 · Source: CVE List
Affected products and versions
2| Product | Source | Version range | Status |
|---|---|---|---|
Acrobat ReaderBrowse Adobe / Acrobat Reader | CVE List | Through 2020.013.20074 | affected |
| Through 2020.001.30018 | affected | ||
| Through 2017.011.30188 | affected | ||
| Through None | affected | ||
Acrobat and ReaderBrowse Adobe / Acrobat and Reader | CISA | Version data not supplied | |
Proofs of concept
1Repository PoCs
GitHubZeusBox/CVE-2021-21017Repository PoCby ZeusBoxStars: 44Not analyzed3 files
References
3nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2021-21017 cisa.govGovernment resource
https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2021-21017