Headline
CVE-2021-39859: Adobe Security Bulletin
Acrobat Reader DC versions 2021.005.20060 (and earlier), 2020.004.30006 (and earlier) and 2017.011.30199 (and earlier) are affected by a Use After Free vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Security update available for Adobe Acrobat and Reader | APSB21-55
Adobe has released security updates for Adobe Acrobat and Reader for Windows and macOS. These updates address multiple critical, important and moderate vulnerabilities. Successful exploitation could lead to arbitrary code execution in the context of the current user.
Adobe recommends users update their software installations to the latest versions by following the instructions below.
The latest product versions are available to end users via one of the following methods:
Users can update their product installations manually by choosing Help > Check for Updates.
The products will update automatically, without requiring user intervention, when updates are detected.
The full Acrobat Reader installer can be downloaded from the Acrobat Reader Download Center.
For IT administrators (managed environments):
Refer to the specific release note version for links to installers.
Install updates via your preferred methodology, such as AIP-GPO, bootstrapper, SCUP/SCCM (Windows), or on macOS, Apple Remote Desktop and SSH.
Adobe categorizes these updates with the following priority ratings and recommends users update their installation to the newest version:
Vulnerability Category
Vulnerability Impact
Severity
CVSS base score
CVSS vector
CVE Number
Type Confusion (CWE-843)
Arbitrary code execution
Critical
7.8
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
CVE-2021-39841
Heap-based Buffer Overflow
(CWE-122)
Arbitrary code execution
Critical
7.8
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
CVE-2021-39863
Information Exposure
(CWE-200)
Arbitrary file system read
Moderate
6.5
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
CVE-2021-39857
CVE-2021-39856
CVE-2021-39855
Out-of-bounds Read
(CWE-125)
Memory leak
Critical
7.7
CVSS:3.0/AV:L/AC:H/PR:N/UI:R/S:C/C:N/I:L/A:H
CVE-2021-39844
Out-of-bounds Read
(CWE-125)
Memory leak
Important
5.5
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
CVE-2021-39861
Out-of-bounds Read
(CWE-125)
Arbitrary file system read
Moderate
3.3
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N
CVE-2021-39858
Out-of-bounds Write
(CWE-787)
Memory leak
Critical
7.8
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
CVE-2021-39843
Stack-based Buffer Overflow
(CWE-121)
Arbitrary code execution
Critical
6.1
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:H
CVE-2021-39846
CVE-2021-39845
Uncontrolled Search Path Element
(CWE-427)
Arbitrary code execution
Important
7.3
CVSS:3.0/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H
CVE-2021-35982
Use After Free
(CWE-416)
Arbitrary code execution
Important
4.4
CVSS:3.0/AV:L/AC:H/PR:L/UI:R/S:U/C:L/I:L/A:N
CVE-2021-39859
Use After Free
(CWE-416)
Arbitrary code execution
Critical
7.8
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
CVE-2021-39840
CVE-2021-39842
CVE-2021-39839
CVE-2021-39838
CVE-2021-39837
CVE-2021-39836
NULL Pointer Dereference (CWE-476)
Memory leak
Important
5.5
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
CVE-2021-39860
NULL Pointer Dereference (CWE-476)
Application denial-of-service
Important
5.5
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
CVE-2021-39852
NULL Pointer Dereference (CWE-476)
Application denial-of-service
Important
5.5
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
CVE-2021-39854
CVE-2021-39853
CVE-2021-39850
CVE-2021-39849
NULL Pointer Dereference (CWE-476)
Application denial-of-service
Important
5.5
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
CVE-2021-39851
Use After Free
(CWE-416)
Arbitrary code execution
Critical
7.8
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
CVE-2021-40725
Use After Free
(CWE-416)
Arbitrary code execution
Critical
7.8
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
CVE-2021-40726
Adobe would like to thank the following for reporting the relevant issues and for working with Adobe to help protect our customers:
Mark Vincent Yason (@MarkYason) working with Trend Micro Zero Day Initiative (CVE-2021-39841, CVE-2021-39836, CVE-2021-39837, CVE-2021-39838, CVE-2021-39839, CVE-2021-39840, CVE-2021-40725, CVE-2021-40726)
Haboob labs (CVE-2021-39859, CVE-2021-39860, CVE-2021-39861, CVE-2021-39843, CVE-2021-39844, CVE-2021-39845, CVE-2021-39846)
Robert Chen (Deep Surfacehttps://deepsurface.com/\) (CVE-2021-35982)
XuPeng from UCAS and Ying Lingyun form QI-ANXIN Technology Research Institute (CVE-2021-39854, CVE-2021-39853, CVE-2021-39852, CVE-2021-39851, CVE-2021-39850, CVE-2021-39849)
j00sean (CVE-2021-39857, CVE-2021-39856, CVE-2021-39855, CVE-2021-39842)
Exodus Intelligence (exodusintel.com) and Andrei Stefan (CVE-2021-39863)
Qiao Li Of Baidu Security Lab working with Trend Micro Zero Day Initiative (CVE-2021-39858)
September 20, 2021: Updated acknowledgement details for CVE-2021-35982.
September 28, 2021: Updated acknowledgement details for CVE-2021-39863.
October 5, 2021: Updated CVSS base score, CVSS vector, and Severity for CVE-2021-39852, CVE-2021-39851, CVE-2021-39863, CVE-2021-39860, CVE-2021-39861. Added data and acknowledgements for CVE-2021-40725 and CVE-2021-40726.
January 18th, 2022: Updated acknowledgement details for CVE-2021-39854, CVE-2021-39853, CVE-2021-39852, CVE-2021-39851, CVE-2021-39850, CVE-2021-39849
January 27th, 2022: Updated CVSS details for CVE-2021-39845, CVE-2021-39846, CVE-2021-39855, CVE-2021-39856, CVE-2021-39860, CVE-2021-39861
For more information, visit https://helpx.adobe.com/security.html, or email [email protected].