Vulnerability record · CVE-2021-39839 · published 29 September 2021
CVE-2021-39839: Adobe Acrobat Reader use-after-free in AcroForm getItem action
Adobe · Acrobat
Adobe Acrobat Reader DC (and related Acrobat products) contain a use-after-free (CWE-416) in the processing of the AcroForm getItem action. A crafted PDF can corrupt memory and lead to code execution in the context of the current user. The flaw affects versions 2021.005.20060 and earlier, 2020.004.30006 and earlier, and 2017.011.30199 and earlier.
Description
Acrobat Reader DC versions 2021.005.20060 (and earlier), 2020.004.30006 (and earlier) and 2017.011.30199 (and earlier) are affected by a use-after-free vulnerability in the processing of the AcroForm getItem action that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Automated analysis
high priorityCVSS 7.8 with high EPSS and code execution impact, though exploitation requires user interaction and no KEV listing is present.
What it is
Adobe Acrobat Reader DC (and related Acrobat products) contain a use-after-free (CWE-416) in the processing of the AcroForm getItem action. A crafted PDF can corrupt memory and lead to code execution in the context of the current user. The flaw affects versions 2021.005.20060 and earlier, 2020.004.30006 and earlier, and 2017.011.30199 and earlier.
Impact
An attacker who gets a victim to open a malicious PDF can execute arbitrary code with the privileges of the logged-in user, potentially leading to full system compromise.
Attack surface
Reached locally by opening a malicious PDF file; the CVSS vector shows no privileges required but user interaction is required, as the victim must open the crafted document.
Exploitation
Not listed in CISA KEV and no public exploit references are provided, but EPSS is high (0.65249, 99.2nd percentile), indicating elevated likelihood of exploitation activity.
What to do
- Apply the Adobe security update referenced in APSB21-55 to move past the affected versions.
- Disable or restrict JavaScript and non-essential AcroForm features in Acrobat Reader where operationally feasible.
- Enforce Protected View / Enhanced Security in Acrobat Reader so untrusted PDFs open in a sandboxed mode.
- Block or quarantine PDF attachments from untrusted sources at the email and web gateway.
- Run Acrobat Reader with least privilege and keep OS-level exploit mitigations enabled.
Detection
- Monitor for Acrobat Reader processes spawning child processes such as cmd.exe, powershell.exe, or scripting hosts.
- Alert on Acrobat Reader crashes or memory corruption events correlated with recently opened PDF files.
- Hunt for PDFs containing AcroForm getItem action objects delivered via email or web downloads.
- Review endpoint telemetry for unusual file writes or network connections originating from Acrobat Reader.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
4 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://helpx.adobe.com/security/products/acrobat/apsb21-55.html | Release NotesVendor Advisory |
| https://helpx.adobe.com/security/products/acrobat/apsb21-55.html | Release NotesVendor Advisory |
Track CVE-2021-39839 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2021-39839), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.