Vulnerability record · CVE-2021-39837 · published 29 September 2021
CVE-2021-39837: Adobe Acrobat Reader use-after-free in AcroForm deleteItemAt action
Adobe · Acrobat
Acrobat Reader DC (2021.005.20060, 2020.004.30006, 2017.011.30199 and earlier) contains a use-after-free in the processing of the AcroForm deleteItemAt action. A crafted PDF can corrupt memory and lead to arbitrary code execution in the context of the current user, so opening an untrusted file is enough to put a workstation at risk.
Description
Acrobat Reader DC versions 2021.005.20060 (and earlier), 2020.004.30006 (and earlier) and 2017.011.30199 (and earlier) are affected by a use-after-free vulnerability in the processing of the AcroForm deleteItemAt action that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Automated analysis
high priorityCVSS 7.8 with high confidentiality, integrity and availability impact plus a very high EPSS score, though no KEV listing or confirmed in-the-wild exploitation is documented.
What it is
Acrobat Reader DC (2021.005.20060, 2020.004.30006, 2017.011.30199 and earlier) contains a use-after-free in the processing of the AcroForm deleteItemAt action. A crafted PDF can corrupt memory and lead to arbitrary code execution in the context of the current user, so opening an untrusted file is enough to put a workstation at risk.
Impact
An attacker who gets a victim to open a malicious PDF can execute arbitrary code with the privileges of the logged-in user, enabling data theft, further payload installation or lateral movement from that host.
Attack surface
Reached locally by opening a malicious PDF in the affected Acrobat Reader builds; no authentication is required, but user interaction (opening the file) is required per the CVSS vector AV:L/UI:R.
Exploitation
Not listed in CISA KEV and no public exploit references are provided, but EPSS is 0.65249 (99.2nd percentile), indicating a high predicted likelihood of exploitation activity.
What to do
- Update Acrobat Reader DC and Acrobat DC to the fixed versions in Adobe advisory APSB21-55 (2021.005.20068, 2020.004.30026, 2017.011.30202 or later).
- If patching cannot be done immediately, restrict or block PDF opening in Acrobat from untrusted sources and enforce Protected View/Enhanced Security.
- Disable or harden JavaScript and non-essential AcroForm features in Acrobat where business use allows.
- Block inbound PDF attachments at the email and web gateways and detach or sandbox them before delivery.
- Run Acrobat with least privilege and keep EDR/ASR rules that block Office and PDF readers from spawning child processes.
Detection
- Monitor for Acrobat Reader processes spawning cmd.exe, powershell.exe, wscript.exe or other unexpected children, which can indicate successful exploitation.
- Hunt for PDF files containing AcroForm deleteItemAt actions or malformed form objects delivered via email or download, using file and mail gateway telemetry.
- Correlate Acrobat crash reports (use-after-free access violations) on endpoints with subsequent suspicious process or network activity.
- Review EDR telemetry for Acrobat reading files from temp or download directories followed by outbound connections to new or low-reputation hosts.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
4 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://helpx.adobe.com/security/products/acrobat/apsb21-55.html | Release NotesVendor Advisory |
| https://helpx.adobe.com/security/products/acrobat/apsb21-55.html | Release NotesVendor Advisory |
Track CVE-2021-39837 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2021-39837), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.