Vulnerability record · CVE-2021-39843 · published 29 September 2021
CVE-2021-39843: Adobe Acrobat Reader DC out-of-bounds write in file parsing
Adobe · Acrobat
Adobe Acrobat Reader DC versions 2021.005.20060, 2020.004.30006 and 2017.011.30199 (and earlier) contain an out-of-bounds write (CWE-787) that can lead to arbitrary code execution in the context of the current user. The flaw is triggered when a victim opens a malicious file, so it is a client-side code execution issue affecting a widely deployed document reader.
Description
Acrobat Reader DC versions 2021.005.20060 (and earlier), 2020.004.30006 (and earlier) and 2017.011.30199 (and earlier) are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Automated analysis
high priorityCVSS 7.8 with high confidentiality, integrity and availability impact and a very high EPSS score, though exploitation requires a victim to open a malicious file and no active exploitation is documented.
What it is
Adobe Acrobat Reader DC versions 2021.005.20060, 2020.004.30006 and 2017.011.30199 (and earlier) contain an out-of-bounds write (CWE-787) that can lead to arbitrary code execution in the context of the current user. The flaw is triggered when a victim opens a malicious file, so it is a client-side code execution issue affecting a widely deployed document reader.
Impact
An attacker who gets a crafted file opened can execute arbitrary code with the privileges of the logged-in user, giving full control of that user's session and data. No privilege escalation beyond the current user is described.
Attack surface
Reached locally by opening a malicious file in the affected Acrobat or Acrobat Reader product; the CVSS vector (AV:L, UI:R, PR:N) indicates user interaction is required and no authentication is needed.
Exploitation
Not listed in CISA KEV and no ransomware usage is documented; EPSS is high at 0.767 (99.5th percentile), and the only references are Adobe vendor advisories with no public exploit or PoC tags.
What to do
- Update Acrobat and Acrobat Reader to the fixed versions in Adobe advisory APSB21-55 or later.
- Where immediate patching is not possible, restrict opening of untrusted PDFs and disable JavaScript and other risky features in the reader.
- Enforce Protected View / Protected Mode and block outbound network access from the reader process.
- Apply email and web gateway filtering to block untrusted PDF attachments and downloads.
- Track affected endpoints with software inventory and prioritize the older 2017 and 2020 branches.
Detection
- Monitor for Acrobat/Reader processes spawning child processes such as cmd.exe, powershell.exe or script hosts.
- Alert on reader process crashes or out-of-bounds write indicators in endpoint telemetry.
- Hunt for PDF files written to temp or user directories shortly before suspicious process creation.
- Review proxy and email logs for PDFs from untrusted senders delivered to endpoints running unpatched versions.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
4 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://helpx.adobe.com/security/products/acrobat/apsb21-55.html | Release NotesVendor Advisory |
| https://helpx.adobe.com/security/products/acrobat/apsb21-55.html | Release NotesVendor Advisory |
Track CVE-2021-39843 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2021-39843), CISA KEV, FIRST EPSS (scores of 2026-09-28). This page is refreshed as NVD updates the record.