VDB
CVE-2021-21088
CVE-2021-21088
PUBLISHED
CVSS 7.800000190734863 HIGH
Acrobat Reader DC versions versions 2020.013.20074 (and earlier), 2020.001.30018 (and earlier) and 2017.011.30188 (and earlier) are affected by a Use After Free vulnerability. An unauthenticated attacker could leverage this vulnerability to achieve arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
EPSS 0.20% · 42.1th percentile
Risk Scores
CVSS 3.1
7.800000190734863
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
EPSS Score
0.20%
42.1th percentile
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| adobe | acrobat_dc | 15.007.20033 |
| Adobe | Acrobat Reader | 0 |
| adobe | acrobat_reader_dc | 15.007.20033 |
| adobe | acrobat_reader | 20.001.30005, 17.011.30180 |
| adobe | acrobat | 17.011.30180, 20.001.30005 |
Timeline
- Sep 6, 2023 CVE Published
- Sep 7, 2023 EPSS Score
- Nov 11, 2023 EPSS Score
- Dec 22, 2023 EPSS Score
- Jan 9, 2024 EPSS Score
- Jan 24, 2024 EPSS Score
- Feb 17, 2024 EPSS Score
- Mar 13, 2024 EPSS Score
- Mar 21, 2024 EPSS Score
- Apr 14, 2024 EPSS Score
- May 5, 2024 EPSS Score
- May 25, 2024 EPSS Score