Vulnerability Details CVE-2021-21089
Acrobat Reader DC versions versions 2020.013.20074 (and earlier), 2020.001.30018 (and earlier) and 2017.011.30188 (and earlier) are affected by an out-of-bounds Read vulnerability. An unauthenticated attacker could leverage this vulnerability to locally escalate privileges in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.007
EPSS Ranking 71.2%
CVSS Severity
CVSS v3 Score 3.3
CVSS v2 Score 4.3
Products affected by CVE-2021-21089
-
cpe:2.3:a:adobe:acrobat_dc:*
-
cpe:2.3:a:adobe:acrobat_dc:17.011.30166
-
cpe:2.3:a:adobe:acrobat_dc:17.011.30171
-
cpe:2.3:a:adobe:acrobat_dc:17.011.30175
-
cpe:2.3:a:adobe:acrobat_dc:20.006.20034
-
cpe:2.3:a:adobe:acrobat_dc:20.006.20042
-
cpe:2.3:a:adobe:acrobat_dc:20.009.20063
-
cpe:2.3:a:adobe:acrobat_dc:20.009.20065
-
cpe:2.3:a:adobe:acrobat_dc:20.009.20067
-
cpe:2.3:a:adobe:acrobat_dc:20.009.20074
-
cpe:2.3:a:adobe:acrobat_dc:20.012.20041
-
cpe:2.3:a:adobe:acrobat_dc:20.012.20043
-
cpe:2.3:a:adobe:acrobat_dc:20.012.20048
-
cpe:2.3:a:adobe:acrobat_dc:20.013.20064
-
cpe:2.3:a:adobe:acrobat_dc:20.013.20066
-
cpe:2.3:a:adobe:acrobat_dc:20.013.20074
-
cpe:2.3:a:adobe:acrobat_reader_dc:*
-
cpe:2.3:a:adobe:acrobat_reader_dc:17.011.30166
-
cpe:2.3:a:adobe:acrobat_reader_dc:17.011.30171
-
cpe:2.3:a:adobe:acrobat_reader_dc:17.011.30175
-
cpe:2.3:a:adobe:acrobat_reader_dc:20.006.20034
-
cpe:2.3:a:adobe:acrobat_reader_dc:20.006.20042
-
cpe:2.3:a:adobe:acrobat_reader_dc:20.009.20063
-
cpe:2.3:a:adobe:acrobat_reader_dc:20.009.20065
-
cpe:2.3:a:adobe:acrobat_reader_dc:20.009.20067
-
cpe:2.3:a:adobe:acrobat_reader_dc:20.009.20074
-
cpe:2.3:a:adobe:acrobat_reader_dc:20.012.20041
-
cpe:2.3:a:adobe:acrobat_reader_dc:20.012.20043
-
cpe:2.3:a:adobe:acrobat_reader_dc:20.012.20048
-
cpe:2.3:a:adobe:acrobat_reader_dc:20.013.20064
-
cpe:2.3:a:adobe:acrobat_reader_dc:20.013.20066
-
cpe:2.3:a:adobe:acrobat_reader_dc:20.013.20074
-
-
cpe:2.3:o:microsoft:windows:-