VDB

CVE-2021-21088

CVE-2021-21088 PUBLISHED CVSS 7.800000190734863 HIGH

Acrobat Reader DC versions versions 2020.013.20074 (and earlier), 2020.001.30018 (and earlier) and 2017.011.30188 (and earlier) are affected by a Use After Free vulnerability. An unauthenticated attacker could leverage this vulnerability to achieve arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

EPSS 0.20% · 42.1th percentile

Risk Scores

CVSS 3.1
7.800000190734863
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
EPSS Score
0.20%
42.1th percentile

Affected Products

VendorProductVersions
adobeacrobat_dc15.007.20033
AdobeAcrobat Reader0
adobeacrobat_reader_dc15.007.20033
adobeacrobat_reader20.001.30005, 17.011.30180
adobeacrobat17.011.30180, 20.001.30005

Timeline

  • Sep 6, 2023 CVE Published
  • Sep 7, 2023 EPSS Score
  • Nov 11, 2023 EPSS Score
  • Dec 22, 2023 EPSS Score
  • Jan 9, 2024 EPSS Score
  • Jan 24, 2024 EPSS Score
  • Feb 17, 2024 EPSS Score
  • Mar 13, 2024 EPSS Score
  • Mar 21, 2024 EPSS Score
  • Apr 14, 2024 EPSS Score
  • May 5, 2024 EPSS Score
  • May 25, 2024 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›