Assessment
Why it matters
CISA lists this vulnerability as known to be exploited; exploitation is confirmed; EPSS is 86.3%; technical severity is CVSS 8.8.
Acrobat Reader DC versions versions 2020.013.20074 (and earlier), 2020.001.30018 (and earlier) and 2017.011.30188 (and earlier) are affected by a heap-based buffer overflow vulnerability. An unauthenticated attacker could leverage this vulnerability to achieve arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Who should care
- Teams operating Acrobat, Acrobat and Reader, Acrobat Dc +2 more
- Vulnerability and exposure management teams
- Security operations teams monitoring exploitation activity
Response plan
What I would do
- Confirm whether Acrobat, Acrobat and Reader, Acrobat Dc +2 more is present in the environment.
- Identify affected versions and establish whether vulnerable services are exposed or reachable.
- Adobe Security advisory APSB21-09
- Review relevant security telemetry for evidence of attempted or successful exploitation.
- Document the remediation decision and track it to verified completion.
Treatment intelligence
Remediation intelligence
Vendor sources are listed before government and third-party guidance. Confirm product applicability and change prerequisites before deployment.
Technical details
- CVSS vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
- CWE
- CWE-122
- Affected versions
- Adobe Acrobat (Start Including 17.0, End Including 17.011.30188 | Start Including 20.0, End Including 20.001.30018); Adobe Acrobat and Reader; Adobe Acrobat Dc (End Including 20.013.20074); Adobe Acrobat Reader (Start Including 17.0, End Including 17.011.30188 | Start Including 20.0, End Including 20.001.300183); Adobe Acrobat Reader Dc (End Including 20.013.20074)
- Fixed versions
- No explicit fixed version is currently recorded.
- Published
- 11 February 2021
- Attack vector
- Network
- Privileges required
- None
- User interaction
- Required
Signal timeline
- CVE published
- Added to CISA KEV
- Latest EPSS score: 86.3%
- Signal calculated at 82