CVE-2021-28545 is a critical vulnerability affecting Adobe Acrobat Reader DC versions 2020.013.20074 (and earlier), 2020.001.30018 (and earlier), and 2017.011.30188 (and earlier), as well as products from Apple and Microsoft. This flaw stems from a missing integrity check, allowing an unauthenticated attacker to manipulate data within a certified PDF without invalidating its original certification. With a CVSS score of 8.1 (HIGH), this vulnerability has a network attack vector and low attack complexity, but requires user interaction for exploitation, as the victim must open the tampered file, leading to high confidentiality and integrity impacts. There is currently no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 17.011.30059, <= 17.011.30188CPE matchmatch criteria | cpe:2.3:a:adobe:acrobat:*:*:*:*:classic:*:*:* | ||
>= 20.001.30005, <= 20.001.30018CPE matchmatch criteria | cpe:2.3:a:adobe:acrobat:*:*:*:*:classic:*:*:* | ||
>= 15.008.20082, <= 20.013.20074CPE matchmatch criteria | cpe:2.3:a:adobe:acrobat_dc:*:*:*:*:continuous:*:*:* | ||
>= 17.011.30059, <= 17.011.30188CPE matchmatch criteria | cpe:2.3:a:adobe:acrobat_reader:*:*:*:*:classic:*:*:* | ||
>= 20.001.30005, <= 20.001.30018CPE matchmatch criteria | cpe:2.3:a:adobe:acrobat_reader:*:*:*:*:classic:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.1 Security Researcher mentions.