CVE-2021-28550
גבוהה 8.8 מנוצלת בשטח (KEV)
ניצול פעיל מאומת — קטלוג CISA KEV
- שם
- Adobe Acrobat and Reader Use-After-Free Vulnerability
- נוסף לקטלוג
- יעד טיפול (פדרלי)
- פעולה נדרשת
- Apply updates per vendor instructions.
תיאור (מקור, אנגלית)
Acrobat Reader DC versions versions 2021.001.20150 (and earlier), 2020.001.30020 (and earlier) and 2017.011.30194 (and earlier) are affected by a Use After Free vulnerability. An unauthenticated attacker could leverage this vulnerability to achieve arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
מדדים
- CVSS 3.1
-
8.8 (HIGH)
מקור הציון: NVD
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H - EPSS — סבירות ניצול
- 52% (אחוזון 100) נכון ל-25/7/2026
- CWE
- CWE-416
מוצרים מושפעים
adobe: acrobat dc; adobe: acrobat reader dc; microsoft: windows; adobe: acrobat; adobe: acrobat reader; apple: macos
קישורים
- https://helpx.adobe.com/security/products/acrobat/apsb21-29.html Release NotesVendor Advisory
- https://helpx.adobe.com/security/products/acrobat/apsb21-29.html Release NotesVendor Advisory
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-202… Third Party AdvisoryUS Government Resource