Acrobat Reader DC versions 2021.005.20060 (and earlier), 2020.004.30006 (and earlier) and 2017.011.30199 (and earlier) are affected by a stack overflow vulnerability due to insecure handling of a crafted PDF file, potentially resulting in memory corruption in the context of the current user. Exploitation requires user interaction in that a victim must open a crafted PDF file in Acrobat Reader.
                
            References
                    | Link | Resource | 
|---|---|
| https://helpx.adobe.com/security/products/acrobat/apsb21-55.html | Release Notes Vendor Advisory | 
| https://helpx.adobe.com/security/products/acrobat/apsb21-55.html | Release Notes Vendor Advisory | 
Configurations
                    Configuration 1 (hide)
| AND | 
            
            
 
  | 
    
Configuration 2 (hide)
| AND | 
            
            
 
  | 
    
Configuration 3 (hide)
| AND | 
            
            
 
  | 
    
Configuration 4 (hide)
| AND | 
            
            
 
  | 
    
History
                    21 Nov 2024, 06:20
| Type | Values Removed | Values Added | 
|---|---|---|
| References | () https://helpx.adobe.com/security/products/acrobat/apsb21-55.html - Release Notes, Vendor Advisory | 
28 Jan 2022, 22:15
| Type | Values Removed | Values Added | 
|---|---|---|
| CWE | CWE-121 | 
06 Oct 2021, 21:17
| Type | Values Removed | Values Added | 
|---|---|---|
| CVSS | 
        v2 :  v3 :  | 
    
        v2 : 5.8
         v3 : 6.1  | 
| CPE | cpe:2.3:a:adobe:acrobat_reader_dc:*:*:*:*:continuous:*:*:* cpe:2.3:o:apple:macos:-:*:*:*:*:*:*:* cpe:2.3:a:adobe:acrobat_dc:*:*:*:*:continuous:*:*:* cpe:2.3:a:adobe:acrobat:*:*:*:*:classic:*:*:* cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:* cpe:2.3:a:adobe:acrobat_reader:*:*:*:*:classic:*:*:*  | 
|
| References | (MISC) https://helpx.adobe.com/security/products/acrobat/apsb21-55.html - Release Notes, Vendor Advisory | |
| CWE | CWE-787 | 
29 Sep 2021, 16:44
| Type | Values Removed | Values Added | 
|---|---|---|
| New CVE | 
Information
                Published : 2021-09-29 16:15
Updated : 2024-11-21 06:20
NVD link : CVE-2021-39845
Mitre link : CVE-2021-39845
CVE.ORG link : CVE-2021-39845
JSON object : View
Products Affected
                adobe
- acrobat_dc
 - acrobat_reader
 - acrobat
 - acrobat_reader_dc
 
apple
- macos
 
microsoft
- windows
 
