← Vulnerability feed

Vulnerability record · CVE-2021-21017 · published 11 February 2021

CVE-2021-21017: Adobe Acrobat and Reader heap buffer overflow via malicious file

Adobe · Acrobat

Adobe Acrobat Reader DC (2020.013.20074, 2020.001.30018, 2017.011.30188 and earlier) contains a heap-based buffer overflow (CWE-122/CWE-787) triggered when a victim opens a crafted file. Successful exploitation allows arbitrary code execution in the context of the current user, making it a serious client-side risk for anyone opening untrusted PDFs.

8.8 CVSS 3.1 High CISA KEV since 3 Nov 2021 EPSS 86% · top 0.3% CWE-122 · Heap-based buffer overflowCWE-787 · Out-of-bounds write
8.8CVSS 3.1 base score, v2 6.8
86%EPSS exploitation probability, 30 days
YesIn CISA KEV, fix deadline passed
4Affected product versions listed by NVD
3References
17 Jun 2026Last modified by NVD

Description

Acrobat Reader DC versions versions 2020.013.20074 (and earlier), 2020.001.30018 (and earlier) and 2017.011.30188 (and earlier) are affected by a heap-based buffer overflow vulnerability. An unauthenticated attacker could leverage this vulnerability to achieve arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 17 September 2026. Confidence: high.

critical priorityIt is a remotely reachable, unauthenticated code-execution flaw in a widely deployed client, listed in CISA KEV with a very high EPSS score and known exploitation.

What it is

Adobe Acrobat Reader DC (2020.013.20074, 2020.001.30018, 2017.011.30188 and earlier) contains a heap-based buffer overflow (CWE-122/CWE-787) triggered when a victim opens a crafted file. Successful exploitation allows arbitrary code execution in the context of the current user, making it a serious client-side risk for anyone opening untrusted PDFs.

Impact

An attacker gains arbitrary code execution with the privileges of the user running Acrobat or Reader, enabling malware installation, data theft or further lateral movement from the victim's workstation.

Attack surface

Reached remotely over the network (AV:N) with no authentication (PR:N), but requires user interaction (UI:R) because the victim must open a malicious file. The record does not specify the exact file format or delivery channel beyond the malicious file requirement.

Exploitation

Listed in CISA KEV since 2021-11-03 with a required remediation due date of 2021-11-17, indicating known exploitation in the wild. EPSS is very high (0.86326, 99.7th percentile), and references are limited to the Adobe advisory and the CISA KEV entry; no public exploit code or PoC is cited in the record.

What to do

  • Apply the Adobe updates referenced in advisory APSB21-09 for Acrobat and Acrobat Reader DC, prioritizing the listed affected versions.
  • Upgrade to a currently supported Acrobat/Reader release and remove or block end-of-life versions such as 2017.011.30188 and earlier.
  • Enforce Protected View/Protected Mode and disable JavaScript in Acrobat Reader where operationally feasible.
  • Block or sandbox untrusted PDF attachments at the email and web gateway, and restrict direct download of PDFs from untrusted sources.
  • Verify remediation against CISA KEV due date 2021-11-17 and track completion for all endpoints running affected versions.

Detection

  • Monitor for Acrobat/Reader processes spawning child processes such as cmd.exe, powershell.exe or scripting hosts, which is abnormal for normal PDF viewing.
  • Hunt for crashes or heap corruption events in AcroRd32.exe/Acrobat.exe via Windows Error Reporting or endpoint telemetry.
  • Inspect email and web proxy logs for PDF attachments or downloads from untrusted senders or newly registered domains delivered to endpoints with affected Acrobat versions.
  • Audit installed Acrobat/Reader versions across the estate and alert on any host still running 2020.013.20074, 2020.001.30018, 2017.011.30188 or earlier.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Exploitation in the wild

CISA added CVE-2021-21017 to the Known Exploited Vulnerabilities catalog on 3 November 2021 as "Adobe Acrobat and Reader Heap-based Buffer Overflow Vulnerability". Required action: Apply updates per vendor instructions. Federal deadline 17 November 2021.

Affected products

4 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2021-21017 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2014-0546Adobe Reader and Acrobat sandbox bypass allows privileged code executionAdobe Reader and Acrobat 10.x before 10.1.11 and 11.x before 11.0.08 on Windows contain a sandbox protection bypass. An attacker can escape the Reade…KEVEPSS 22%analysed9.8CVE-2013-3346Adobe Reader and Acrobat memory corruption allows code executionAdobe Reader and Acrobat 9.x before 9.5.5, 10.x before 10.1.7, and 11.x before 11.0.03 contain an out-of-bounds write (CWE-787) that corrupts memory.…KEVEPSS 79%analysed9.8CVE-2013-2729Adobe Reader and Acrobat integer overflow allows code executionAdobe Reader and Acrobat contain an integer overflow (CWE-190) that can be triggered by unspecified vectors, leading to arbitrary code execution. It …KEVEPSS 67%analysed9.8CVE-2011-2462Adobe Reader and Acrobat U3D memory corruption code executionAn out-of-bounds write in the U3D component of Adobe Reader and Acrobat allows remote attackers to corrupt memory and execute arbitrary code. The fla…KEVEPSS 89%analysed8.8CVE-2021-28550Adobe Acrobat and Reader use-after-free allows code executionAdobe Acrobat Reader DC (2021.001.20150, 2020.001.30020, 2017.011.30194 and earlier) and related Acrobat products contain a use-after-free (CWE-416) …KEVEPSS 52%analysed8.8CVE-2018-4990Adobe Acrobat and Reader double free allows code executionAdobe Acrobat and Reader contain a double free (CWE-415) in versions 2018.011.20038 and earlier, 2017.011.30079 and earlier, and 2015.006.30417 and e…KEVEPSS 36%analysed8.8CVE-2014-0496Adobe Reader and Acrobat use-after-free code executionAdobe Reader and Acrobat 10.x before 10.1.9 and 11.x before 11.0.06 on Windows and Mac OS X contain a use-after-free (CWE-416) that allows arbitrary …KEVEPSS 40%analysed8.8CVE-2011-0611Adobe Flash Player type confusion allows remote code executionAdobe Flash Player, Adobe AIR and the Authplay component in Adobe Reader/Acrobat contain a type confusion flaw (CWE-843) reachable through crafted Fl…KEVEPSS 99%analysed

Source: NIST National Vulnerability Database (record CVE-2021-21017), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.