Vulnerability record · CVE-2021-21017 · published 11 February 2021
CVE-2021-21017: Adobe Acrobat and Reader heap buffer overflow via malicious file
Adobe · Acrobat
Adobe Acrobat Reader DC (2020.013.20074, 2020.001.30018, 2017.011.30188 and earlier) contains a heap-based buffer overflow (CWE-122/CWE-787) triggered when a victim opens a crafted file. Successful exploitation allows arbitrary code execution in the context of the current user, making it a serious client-side risk for anyone opening untrusted PDFs.
Description
Acrobat Reader DC versions versions 2020.013.20074 (and earlier), 2020.001.30018 (and earlier) and 2017.011.30188 (and earlier) are affected by a heap-based buffer overflow vulnerability. An unauthenticated attacker could leverage this vulnerability to achieve arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Automated analysis
critical priorityIt is a remotely reachable, unauthenticated code-execution flaw in a widely deployed client, listed in CISA KEV with a very high EPSS score and known exploitation.
What it is
Adobe Acrobat Reader DC (2020.013.20074, 2020.001.30018, 2017.011.30188 and earlier) contains a heap-based buffer overflow (CWE-122/CWE-787) triggered when a victim opens a crafted file. Successful exploitation allows arbitrary code execution in the context of the current user, making it a serious client-side risk for anyone opening untrusted PDFs.
Impact
An attacker gains arbitrary code execution with the privileges of the user running Acrobat or Reader, enabling malware installation, data theft or further lateral movement from the victim's workstation.
Attack surface
Reached remotely over the network (AV:N) with no authentication (PR:N), but requires user interaction (UI:R) because the victim must open a malicious file. The record does not specify the exact file format or delivery channel beyond the malicious file requirement.
Exploitation
Listed in CISA KEV since 2021-11-03 with a required remediation due date of 2021-11-17, indicating known exploitation in the wild. EPSS is very high (0.86326, 99.7th percentile), and references are limited to the Adobe advisory and the CISA KEV entry; no public exploit code or PoC is cited in the record.
What to do
- Apply the Adobe updates referenced in advisory APSB21-09 for Acrobat and Acrobat Reader DC, prioritizing the listed affected versions.
- Upgrade to a currently supported Acrobat/Reader release and remove or block end-of-life versions such as 2017.011.30188 and earlier.
- Enforce Protected View/Protected Mode and disable JavaScript in Acrobat Reader where operationally feasible.
- Block or sandbox untrusted PDF attachments at the email and web gateway, and restrict direct download of PDFs from untrusted sources.
- Verify remediation against CISA KEV due date 2021-11-17 and track completion for all endpoints running affected versions.
Detection
- Monitor for Acrobat/Reader processes spawning child processes such as cmd.exe, powershell.exe or scripting hosts, which is abnormal for normal PDF viewing.
- Hunt for crashes or heap corruption events in AcroRd32.exe/Acrobat.exe via Windows Error Reporting or endpoint telemetry.
- Inspect email and web proxy logs for PDF attachments or downloads from untrusted senders or newly registered domains delivered to endpoints with affected Acrobat versions.
- Audit installed Acrobat/Reader versions across the estate and alert on any host still running 2020.013.20074, 2020.001.30018, 2017.011.30188 or earlier.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2021-21017 to the Known Exploited Vulnerabilities catalog on 3 November 2021 as "Adobe Acrobat and Reader Heap-based Buffer Overflow Vulnerability". Required action: Apply updates per vendor instructions. Federal deadline 17 November 2021.
Affected products
4 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://helpx.adobe.com/security/products/acrobat/apsb21-09.html | Vendor Advisory |
| https://helpx.adobe.com/security/products/acrobat/apsb21-09.html | Vendor Advisory |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2021-21017 | Third Party AdvisoryUS Government Resource |
Track CVE-2021-21017 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2021-21017), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.