CVE-2021-21017 is a critical heap-based buffer overflow vulnerability affecting Adobe Acrobat Reader DC versions 2020.013.20074 and earlier, 2020.001.30018 and earlier, and 2017.011.30188 and earlier, impacting users across Adobe, Apple, and Microsoft platforms. This vulnerability carries a high CVSS score of 8.8, indicating that an unauthenticated attacker could achieve arbitrary code execution with high confidentiality, integrity, and availability impact if a user opens a malicious file. Notably, this vulnerability is actively exploited in the wild, as confirmed by its inclusion in the KEV catalog and media coverage from BleepingComputer and SecurityWeek. Despite no public exploit code on Metasploit, Nuclei, or ExploitDB, there is significant community discussion, with 12 mentions, highlighting its importance.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 17.0, <= 17.011.30188CPE matchmatch criteria | cpe:2.3:a:adobe:acrobat:*:*:*:*:classic:*:*:* | ||
>= 20.0, <= 20.001.30018CPE matchmatch criteria | cpe:2.3:a:adobe:acrobat:*:*:*:*:classic:*:*:* | ||
<= 20.013.20074CPE matchmatch criteria | cpe:2.3:a:adobe:acrobat_dc:*:*:*:*:continuous:*:*:* | ||
>= 17.0, <= 17.011.30188CPE matchmatch criteria | cpe:2.3:a:adobe:acrobat_reader:*:*:*:*:classic:*:*:* | ||
>= 20.0, <= 20.001.300183CPE matchmatch criteria | cpe:2.3:a:adobe:acrobat_reader:*:*:*:*:classic:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.