← Back to browse · API

CVE-2021-21796

Severity
HIGH
CVSS
8.8
EPSS
0.15777
Risk score
40.72
CISA KEV
No
PoC
No
Published
2021-10-18
Modified
2024-08-03
First seen
2026-08-08
Aliases
EUVD-2021-8968, GHSA-XV8Q-FW76-648M
Products
Nitro:Nitro Pro Nitro Pro 13.31.0.605,Nitro Pro 13.33.2.645
Sources
euvd EUVD-2021-8968

Description

An exploitable use-after-free vulnerability exists in the JavaScript implementation of Nitro Pro PDF. A specially crafted document can cause an object containing the path to a document to be destroyed and then later reused, resulting in a use-after-free vulnerability, which can lead to code execution under the context of the application. An attacker can convince a user to open a document to trigger this vulnerability.

References