Vulnerability record · CVE-2021-39836 · published 29 September 2021
CVE-2021-39836: Adobe Acrobat Reader use-after-free in AcroForm buttonGetIcon action
Adobe · Acrobat
Acrobat Reader DC (and related Acrobat products) contain a use-after-free (CWE-416) in the processing of the AcroForm buttonGetIcon action. A crafted PDF can corrupt memory and lead to arbitrary code execution in the context of the current user. The flaw affects versions 2021.005.20060, 2020.004.30006 and 2017.011.30199 and earlier per the advisory.
Description
Acrobat Reader DC versions 2021.005.20060 (and earlier), 2020.004.30006 (and earlier) and 2017.011.30199 (and earlier) are affected by a use-after-free vulnerability in the processing of the AcroForm buttonGetIcon action that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Automated analysis
high priorityCVSS 7.8 with full confidentiality, integrity and availability impact and a very high EPSS score, though exploitation requires the victim to open a malicious file and no KEV listing or public exploit is confirmed.
What it is
Acrobat Reader DC (and related Acrobat products) contain a use-after-free (CWE-416) in the processing of the AcroForm buttonGetIcon action. A crafted PDF can corrupt memory and lead to arbitrary code execution in the context of the current user. The flaw affects versions 2021.005.20060, 2020.004.30006 and 2017.011.30199 and earlier per the advisory.
Impact
An attacker who gets a victim to open a malicious PDF can execute arbitrary code with the privileges of the logged-in user, giving full control of that user's session and data.
Attack surface
Reached locally by opening a crafted PDF; the CVSS vector (AV:L, UI:R, PR:N) indicates no authentication is needed but user interaction (opening the file) is required.
Exploitation
Not listed in CISA KEV and no public exploit or ransomware use is documented in the record, but EPSS is high at 0.695 (99.3rd percentile), indicating elevated likelihood of exploitation activity.
What to do
- Update Acrobat Reader DC and Acrobat to the fixed versions in Adobe advisory APSB21-55 (2021.005.20068, 2020.004.30026, 2017.011.30202 or later).
- Where immediate patching is not possible, restrict or disable JavaScript and the buttonGetIcon-related form features via policy, and block untrusted PDFs at the gateway.
- Enforce Protected View / Protected Mode and disable automatic opening of PDFs from email and web downloads.
- Run Acrobat with least privilege and consider application allowlisting to limit post-exploitation impact.
Detection
- Monitor for Acrobat Reader processes spawning child processes such as cmd.exe, powershell.exe or script hosts, which is abnormal for PDF viewing.
- Alert on Acrobat Reader crashes or memory-corruption events (Windows Error Reporting / crash dumps) tied to opening PDFs.
- Hunt for PDFs containing AcroForm buttonGetIcon actions or embedded JavaScript delivered via email or web download.
- Track endpoint and email telemetry for PDFs from untrusted sources opened by high-value users.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
4 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://helpx.adobe.com/security/products/acrobat/apsb21-55.html | Release NotesVendor Advisory |
| https://helpx.adobe.com/security/products/acrobat/apsb21-55.html | Release NotesVendor Advisory |
Track CVE-2021-39836 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2021-39836), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.