IT

Tracker / CVE-2021-44714

CVE-2021-44714

Low 2.5

Acrobat Reader DC version 21.007.20099 (and earlier), 20.004.30017 (and earlier) and 17.011.30204 (and earlier) are affected by a Violation of Secure Design Principles that could lead to a Security feature bypass. Acrobat Reader DC displays a warning message when a user clicks on a PDF file, which could be used by an attacker to mislead the user. In affected versions, this warning message does not include custom protocols when used by the sender. User interaction is required to abuse this vulnerability as they would need to click 'allow' on the warning message of a malicious file.

Affected products and versions

adobe acrobat · 17.011.30059 → 17.011.30204
adobe acrobat · 20.001.30005 → 20.004.30017
adobe acrobat_dc · 15.008.20082 → 21.007.20099
adobe acrobat_reader · 17.011.30059 → 17.011.30204
adobe acrobat_reader · 20.001.30005 → 20.004.30017
adobe acrobat_reader_dc · 15.008.20082 → 21.007.20099

Analysis

This page is not indexable yet.Until it carries original analysis — what it actually exposes, how to check in two minutes whether a system was touched, what to do if it was — the page stays noindex. The database decides that, not the template.

References