Vulnerability record · CVE-2021-28554 · published 24 August 2021
CVE-2021-28554: Adobe Acrobat Reader DC out-of-bounds read allows code execution
Adobe · Acrobat Dc
Adobe Acrobat Reader DC (and Acrobat) versions 2021.001.20155, 2020.001.30025 and 2017.011.30196 and earlier contain an out-of-bounds read (CWE-125). An unauthenticated attacker can trigger it with a crafted file to execute arbitrary code in the context of the current user. Because the product is widely deployed for opening untrusted documents, the flaw matters for any environment where users open PDFs from external sources.
Description
Acrobat Reader DC versions versions 2021.001.20155 (and earlier), 2020.001.30025 (and earlier) and 2017.011.30196 (and earlier) are affected by an Out-of-bounds Read vulnerability. An unauthenticated attacker could leverage this vulnerability to achieve arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Automated analysis
high priorityCVSS 7.8 with full confidentiality, integrity and availability impact plus a very high EPSS score, though exploitation requires the user to open a malicious file and no KEV listing exists.
What it is
Adobe Acrobat Reader DC (and Acrobat) versions 2021.001.20155, 2020.001.30025 and 2017.011.30196 and earlier contain an out-of-bounds read (CWE-125). An unauthenticated attacker can trigger it with a crafted file to execute arbitrary code in the context of the current user. Because the product is widely deployed for opening untrusted documents, the flaw matters for any environment where users open PDFs from external sources.
Impact
Successful exploitation gives the attacker arbitrary code execution with the privileges of the user who opened the file. That can lead to data theft, further compromise of the host, or installation of additional malware.
Attack surface
Reached locally by opening a malicious file; the CVSS vector shows AV:L, PR:N and UI:R, so no authentication is needed but a victim must open the crafted document. No network service or remote pre-auth path is described.
Exploitation
Not listed in CISA KEV, so no confirmed in-the-wild exploitation is recorded here. EPSS is high (0.46031 probability, 98.752 percentile), indicating elevated likelihood of attempted exploitation, and the references are vendor advisories only with no public exploit tag.
What to do
- Update Acrobat Reader DC and Acrobat to the fixed versions in Adobe advisories apsb21-29 and apsb21-37 (2021.001.20155, 2020.001.30025, 2017.011.30196 or later as applicable).
- Where immediate patching is not possible, restrict or disable JavaScript and other non-essential features in Acrobat Reader and enforce Protected View.
- Block or sandbox opening of PDFs from untrusted sources and route them through a content-disarm or conversion service.
- Run Acrobat Reader with least privilege and keep the host patched to reduce post-exploitation impact.
Detection
- Monitor for Acrobat Reader processes spawning child processes such as cmd.exe, powershell.exe or script hosts, which is abnormal for normal PDF viewing.
- Alert on Acrobat Reader crashes or out-of-bounds read indicators in application or endpoint logs tied to recently opened documents.
- Hunt for PDF files written to user temp or download directories shortly before suspicious process creation.
- Track endpoint telemetry for known post-exploitation behavior from Acrobat Reader, including unusual file writes or network connections.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
4 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://helpx.adobe.com/security/products/acrobat/apsb21-29.html | Not Applicable |
| https://helpx.adobe.com/security/products/acrobat/apsb21-37.html | Vendor Advisory |
| https://helpx.adobe.com/security/products/acrobat/apsb21-29.html | Not Applicable |
Track CVE-2021-28554 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2021-28554), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.