← Back to browse · API

CVE-2021-39840

Severity
HIGH
CVSS
7.8
EPSS
0.50626
Risk score
48.92
CISA KEV
No
PoC
No
Published
2021-09-29
Modified
2024-09-16
First seen
2026-08-07
Aliases
EUVD-2021-26197, GHSA-JWQ3-RF5C-W7RP
Products
Adobe:Acrobat Reader unspecified ≤17.0-Classic 2021 July, Adobe:Acrobat Reader unspecified ≤20.0-Classic 2021 July, Adobe:Acrobat Reader unspecified ≤DC 2021 July, Adobe:Acrobat Reader unspecified ≤None
Sources
euvd EUVD-2021-26197

Description

Acrobat Reader DC versions 2021.005.20060 (and earlier), 2020.004.30006 (and earlier) and 2017.011.30199 (and earlier) are affected by a use-after-free vulnerability when processing AcroForms that could result in arbitrary code execution in the context of the current user. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file.

References