CVE-2021-35986
Acrobat Reader DC versions 2021.005.20054 (and earlier), 2020.004.30005 (and earlier) and 2017.011.30197 (and earlier) are affected by an Type Confusion vulnerability.
Does this matter?
Lower severity and a low EPSS score (2.72%). Track it; it rarely justifies an emergency change on its own.
Description
Acrobat Reader DC versions 2021.005.20054 (and earlier), 2020.004.30005 (and earlier) and 2017.011.30197 (and earlier) are affected by an Type Confusion vulnerability. An unauthenticated attacker could leverage this vulnerability to read arbitrary system information in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
- CVSS 3.1
- 3.3 LOWCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N
- EPSS
- 2.72% probability · 85th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-843
- Affected
- adobe/acrobat dc · adobe/acrobat reader dc
- Source
- psirt@adobe.com
References
- https://helpx.adobe.com/security/products/acrobat/apsb21-51.htmlRelease Notes, Vendor Advisory
- https://www.zerodayinitiative.com/advisories/ZDI-21-1145/Third Party Advisory, VDB Entry
- https://helpx.adobe.com/security/products/acrobat/apsb21-51.htmlRelease Notes, Vendor Advisory
- https://www.zerodayinitiative.com/advisories/ZDI-21-1145/Third Party Advisory, VDB Entry
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.