Coming Soon...

Q-CERT website is currently under maintenance. We should be back shortly. Thank you for yor patience.

Multiple Critical and Important Vulnerabilities in Adobe Acrobat and Reader

Issued: 
Wednesday, 29 September, 2021
Last Revision: 
Wednesday, 29 September, 2021
Vendor: 
Severity Level: 
Summary: 

Adobe has released security update to address the multiple Critical and Important vulnerabilities affecting both Windows and macOS for Adobe Acrobat and Reader. Successful exploitation could lead to arbitrary code execution in the context of the current user.  

 

Organizations are advised to apply patches as soon as possible, particularly patches for critical and important vulnerabilities. 

 

 

        CVE

              Description 

CVSS3.0 Score

CVE-2021-39841

Arbitrary code execution

7.8

CVE-2021-39863

Arbitrary code execution

8.8

CVE-2021-39844

Memory Leak

7.7

CVE-2021-39843

Memory Leak

7.8

CVE-2021-39846

CVE-2021-39845

Arbitrary code execution

7.7

CVE-2021-39840

CVE-2021-39842

CVE-2021-39839

CVE-2021-39838

CVE-2021-39837

CVE-2021-39836

Arbitrary code execution

7.8

CVE-2021-39852

Application denial-of-service

7.2

 

 

Table 1: Vulnerability details 

 

 

 

Product

Track

     Affected Versions

Platform

Acrobat DC 

Continuous 

 

2021.005.20060 and earlier versions          

Windows

Acrobat Reader DC

Continuous 

2021.005.20060 and earlier versions          

Windows

Acrobat DC 

Continuous 

 

2021.005.20058 and earlier versions          

macOS

Acrobat Reader DC

Continuous 

 

2021.005.20058 and earlier versions          

macOS

Acrobat 2020

Classic

2020           

2020.004.30006 and earlier versions

Windows & macOS

Acrobat

Reader 2020

Classic

2020           

2020.004.30006 and earlier versions

Windows & macOS

Acrobat 2017

Classic 2017

2017.011.30199 and earlier versions          

Windows & macOS

Acrobat

Reader 2017

Classic 2017

2017.011.30199 and earlier versions          

Windows & macOS

 

                                                                                          Table 2: Vulnerable versions

 

 

 

Recommendation: 

Adobe recommends users update their software installations to the newest versions by following the instructions below.    

 

The latest product versions are available to end users via one of the following methods:

  • Users can update their product installations manually by choosing Help > Check for Updates.     
  • The products will update automatically, without requiring user intervention, when updates are detected.      
  • The full Acrobat Reader installer can be downloaded from the Acrobat Reader Download Center.    

For IT administrators (managed environments):     

  • Refer to the specific release note version for links to installers.     
  • Install updates via your preferred methodology, such as AIP-GPO, bootstrapper, SCUP/SCCM (Windows), or on macOS, Apple Remote Desktop and SSH.