Adobe Security Bulletin

Security update available for Adobe Acrobat and Reader | APSB21-55

Bulletin ID

Date Published

Priority

APSB21-55

September 14, 2021

2

Summary

Adobe has released security updates for Adobe Acrobat and Reader for Windows and macOS. These updates address  multiple criticalimportant and moderate vulnerabilities. Successful exploitation could lead to arbitrary code execution in the context of the current user.  

 

Affected Versions

Product

Track

Affected Versions

Platform

Acrobat DC 

Continuous 

2021.005.20060 and earlier versions          

Windows

Acrobat Reader DC

Continuous 

2021.005.20060 and earlier versions          

Windows

Acrobat DC 

Continuous 

2021.005.20058 and earlier versions          

macOS

Acrobat Reader DC

Continuous 

2021.005.20058 and earlier versions          

macOS

 

 

 

 

Acrobat 2020

Classic 2020           

2020.004.30006 and earlier versions

Windows & macOS

Acrobat Reader 2020

Classic 2020           

2020.004.30006 and earlier versions

Windows & macOS

 

 

 

 

Acrobat 2017

Classic 2017

2017.011.30199  and earlier versions          

Windows & macOS

Acrobat Reader 2017

Classic 2017

2017.011.30199  and earlier versions          

Windows & macOS

Solution

Adobe recommends users update their software installations to the latest versions by following the instructions below.    

The latest product versions are available to end users via one of the following methods:    

  • Users can update their product installations manually by choosing Help > Check for Updates.     

  • The products will update automatically, without requiring user intervention, when updates are detected.      

  • The full Acrobat Reader installer can be downloaded from the Acrobat Reader Download Center.     

For IT administrators (managed environments):     

  • Refer to the specific release note version for links to installers.     

  • Install updates via your preferred methodology, such as AIP-GPO, bootstrapper, SCUP/SCCM (Windows), or on macOS, Apple Remote Desktop and SSH.     

   

Adobe categorizes these updates with the following priority ratings and recommends users update their installation to the newest version:    

Product

Track

Updated Versions

Platform

Priority Rating

Availability

Acrobat DC

Continuous

2021.007.20091 

Windows and macOS

2

Acrobat Reader DC

Continuous

2021.007.20091 

Windows and macOS

2

Release Notes     

 

 

 

 

 

 

Acrobat 2020

Classic 2020           

2020.004.30015

Windows and macOS     

2

Acrobat Reader 2020

Classic 2020           

2020.004.30015

Windows and macOS     

2

 

 

 

 

 

 

Acrobat 2017

Classic 2017

2017.011.30202

Windows and macOS

2

Acrobat Reader 2017

Classic 2017

2017.011.30202

Windows and macOS

2

Vulnerability Details

Vulnerability Category Vulnerability Impact Severity CVSS base score 
CVSS vector
CVE Number

Type Confusion (CWE-843)

Arbitrary code execution

Critical 

7.8

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

CVE-2021-39841

Heap-based Buffer Overflow

(CWE-122)

Arbitrary code execution

Critical  

7.8

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

CVE-2021-39863

Information Exposure

(CWE-200)

Arbitrary file system read

Moderate

6.5

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N

CVE-2021-39857

CVE-2021-39856

CVE-2021-39855

Out-of-bounds Read

(CWE-125)

Memory leak

Critical   

7.7

CVSS:3.0/AV:L/AC:H/PR:N/UI:R/S:C/C:N/I:L/A:H

CVE-2021-39844

Out-of-bounds Read

(CWE-125)

Memory leak

Important

5.5

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N

CVE-2021-39861

Out-of-bounds Read

(CWE-125)

Arbitrary file system read

Moderate

3.3

 

CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N

CVE-2021-39858

Out-of-bounds Write

(CWE-787)

Memory leak

Critical 

7.8

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

CVE-2021-39843

Stack-based Buffer Overflow 

(CWE-121)

Arbitrary code execution

Critical   

6.1

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:H

CVE-2021-39846

CVE-2021-39845

Uncontrolled Search Path Element

(CWE-427)

Arbitrary code execution

Important 

7.3

CVSS:3.0/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H

CVE-2021-35982

Use After Free

(CWE-416)

Arbitrary code execution

Important

4.4

CVSS:3.0/AV:L/AC:H/PR:L/UI:R/S:U/C:L/I:L/A:N

CVE-2021-39859

Use After Free

(CWE-416)

Arbitrary code execution

Critical 

7.8

CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

CVE-2021-39840

CVE-2021-39842

CVE-2021-39839

CVE-2021-39838

CVE-2021-39837

CVE-2021-39836

NULL Pointer Dereference (CWE-476)

Memory leak

Important

5.5

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N

CVE-2021-39860

NULL Pointer Dereference (CWE-476)

Application denial-of-service

Important  

5.5

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

CVE-2021-39852

NULL Pointer Dereference (CWE-476)

Application denial-of-service

Important

5.5

CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

CVE-2021-39854

CVE-2021-39853

CVE-2021-39850

CVE-2021-39849

 

NULL Pointer Dereference (CWE-476)

Application denial-of-service

Important  

5.5

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H

 CVE-2021-39851

Use After Free

(CWE-416)

Arbitrary code execution
Critical   
7.8 CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
CVE-2021-40725

Use After Free

(CWE-416)

Arbitrary code execution
Critical   
7.8 CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
CVE-2021-40726

Acknowledgements

Adobe would like to thank the following for reporting the relevant issues and for working with Adobe to help protect our customers:   

  • Mark Vincent Yason (@MarkYason) working with Trend Micro Zero Day Initiative (CVE-2021-39841, CVE-2021-39836, CVE-2021-39837, CVE-2021-39838, CVE-2021-39839, CVE-2021-39840, CVE-2021-40725, CVE-2021-40726)
  • Haboob labs (CVE-2021-39859, CVE-2021-39860, CVE-2021-39861, CVE-2021-39843, CVE-2021-39844, CVE-2021-39845, CVE-2021-39846)
  • Robert Chen (Deep Surface<https://deepsurface.com/>) (CVE-2021-35982)
  • XuPeng from UCAS and Ying Lingyun form QI-ANXIN Technology Research Institute (CVE-2021-39854, CVE-2021-39853, CVE-2021-39852, CVE-2021-39851, CVE-2021-39850, CVE-2021-39849)
  • j00sean (CVE-2021-39857, CVE-2021-39856, CVE-2021-39855, CVE-2021-39842)
  • Exodus Intelligence (exodusintel.com) and Andrei Stefan (CVE-2021-39863)
  • Qiao Li Of Baidu Security Lab working with Trend Micro Zero Day Initiative (CVE-2021-39858)

Revisions

September 20, 2021: Updated acknowledgement details for CVE-2021-35982.

September 28, 2021: Updated acknowledgement details for CVE-2021-39863.

October 5, 2021: Updated CVSS base score, CVSS vector, and Severity for CVE-2021-39852, CVE-2021-39851, CVE-2021-39863, CVE-2021-39860, CVE-2021-39861. Added data and acknowledgements for CVE-2021-40725 and CVE-2021-40726.

January 18th, 2022: Updated acknowledgement details for CVE-2021-39854, CVE-2021-39853, CVE-2021-39852, CVE-2021-39851, CVE-2021-39850, CVE-2021-39849

January 27th, 2022: Updated CVSS details for CVE-2021-39845, CVE-2021-39846, CVE-2021-39855, CVE-2021-39856, CVE-2021-39860, CVE-2021-39861



 

 


For more information, visit https://helpx.adobe.com/security.html, or email PSIRT@adobe.com.

Get help faster and easier

New user?