CVE-2021-28550 is a Use After Free vulnerability affecting Adobe Acrobat Reader DC on Windows, macOS, and Linux, allowing unauthenticated attackers to achieve arbitrary code execution. This high-severity vulnerability (CVSS 8.8) requires user interaction, specifically opening a malicious file, but has a low attack complexity. It is actively exploited in the wild, as indicated by its presence in the KEV catalog and media coverage detailing its use in Subzero malware campaigns. Despite no public exploit code in Metasploit, Nuclei, or ExploitDB, the vulnerability has garnered significant community discussion and media attention.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 2017.011.30194CPE match | cpe:2.3:a:adobe:acrobat_reader:*:*:*:*:*:*:*:* | ||
<= 2020.001.30020CPE match | cpe:2.3:a:adobe:acrobat_reader:*:*:*:*:*:*:*:* | ||
<= 2021.001.20150CPE match | cpe:2.3:a:adobe:acrobat_reader:*:*:*:*:*:*:*:* | ||
>= 15.008.20082, <= 21.001.20150CPE matchmatch criteria | cpe:2.3:a:adobe:acrobat_dc:*:*:*:*:continuous:*:*:* | ||
>= 15.008.20082, <= 21.001.20150CPE matchmatch criteria | cpe:2.3:a:adobe:acrobat_reader_dc:*:*:*:*:continuous:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.