SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2021-21042

Acrobat Reader DC versions 2020.013.20074 (and earlier), 2020.001.30018 (and earlier) and 2017.011.30188 (and earlier) are affected by an Out-of-bounds Read vulnerability that could lead to arbitrary disclosure of information in the memory stack.

MEDIUM 6.5EPSS 14.7%

Does this matter?

EPSS puts the probability of exploitation in the next 30 days at 14.7%, higher than 96% of all known CVEs. Patch or mitigate before the next change window.

Description

Acrobat Reader DC versions 2020.013.20074 (and earlier), 2020.001.30018 (and earlier) and 2017.011.30188 (and earlier) are affected by an Out-of-bounds Read vulnerability that could lead to arbitrary disclosure of information in the memory stack. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

CVSS 3.1
6.5 MEDIUMCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
EPSS
14.70% probability · 96th percentile
CISA KEV
Not listed
Weakness
CWE-125
Affected
adobe/acrobat · adobe/acrobat dc · adobe/acrobat reader · adobe/acrobat reader dc
Source
psirt@adobe.com

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.