CVE-2021-28636
Adobe Acrobat Reader Unquoted Search Path Vulnerability
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
Acrobat Reader DC versions 2021.005.20054 (and earlier), 2020.004.30005 (and earlier) and 2017.011.30197 (and earlier) are affected by an Uncontrolled Search Path Element vulnerability. An attacker with access to the victim's C:/ folder could leverage this vulnerability to achieve arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Acrobat Reader DC versiones 2021.005.20054 (y anteriores), 2020.004.30005 (y anteriores), y 2017.011.30197 (y anteriores), están afectadas por una vulnerabilidad de Elemento de Ruta de Búsqueda no Controlada. Un atacante con acceso a la carpeta C:/ de la víctima podría aprovechar esta vulnerabilidad para lograr una ejecución de código arbitrario en el contexto del usuario actual. Una explotación de este problema requiere una interacción del usuario, ya que la víctima debe abrir un archivo malicioso.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2021-03-16 CVE Reserved
- 2021-08-20 CVE Published
- 2023-03-13 EPSS Updated
- 2024-09-16 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-427: Uncontrolled Search Path Element
CAPEC
References (1)
URL | Tag | Source |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|---|---|
https://helpx.adobe.com/security/products/acrobat/apsb21-51.html | 2021-08-31 |
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Adobe Search vendor "Adobe" | Acrobat Dc Search vendor "Adobe" for product "Acrobat Dc" | >= 15.008.20082 <= 21.005.20054 Search vendor "Adobe" for product "Acrobat Dc" and version " >= 15.008.20082 <= 21.005.20054" | continuous |
Affected
| ||||||
Adobe Search vendor "Adobe" | Acrobat Dc Search vendor "Adobe" for product "Acrobat Dc" | >= 17.011.30059 <= 17.011.30197 Search vendor "Adobe" for product "Acrobat Dc" and version " >= 17.011.30059 <= 17.011.30197" | classic |
Affected
| ||||||
Adobe Search vendor "Adobe" | Acrobat Dc Search vendor "Adobe" for product "Acrobat Dc" | >= 20.001.30005 <= 20.004.30005 Search vendor "Adobe" for product "Acrobat Dc" and version " >= 20.001.30005 <= 20.004.30005" | classic |
Affected
| ||||||
Adobe Search vendor "Adobe" | Acrobat Reader Dc Search vendor "Adobe" for product "Acrobat Reader Dc" | >= 15.008.20082 <= 21.005.20054 Search vendor "Adobe" for product "Acrobat Reader Dc" and version " >= 15.008.20082 <= 21.005.20054" | continuous |
Affected
| ||||||
Adobe Search vendor "Adobe" | Acrobat Reader Dc Search vendor "Adobe" for product "Acrobat Reader Dc" | >= 17.011.30059 <= 17.011.30197 Search vendor "Adobe" for product "Acrobat Reader Dc" and version " >= 17.011.30059 <= 17.011.30197" | classic |
Affected
| ||||||
Adobe Search vendor "Adobe" | Acrobat Reader Dc Search vendor "Adobe" for product "Acrobat Reader Dc" | >= 20.001.30005 <= 20.004.30005 Search vendor "Adobe" for product "Acrobat Reader Dc" and version " >= 20.001.30005 <= 20.004.30005" | classic |
Affected
|