← Back to browse · API

CVE-2021-40728

Severity
HIGH
CVSS
7.8
EPSS
0.54627
Risk score
50.32
CISA KEV
No
PoC
No
Published
2021-10-15
Modified
2025-04-23
First seen
2026-08-07
Aliases
EUVD-2021-27893, GHSA-PQ3Q-H37W-5953
Products
Adobe:Acrobat Reader unspecified ≤17.011.30202, Adobe:Acrobat Reader unspecified ≤20.004.30015, Adobe:Acrobat Reader unspecified ≤21.007.20095, Adobe:Acrobat Reader unspecified ≤21.007.20096
Sources
euvd EUVD-2021-27893

Description

Adobe Acrobat Reader DC version 21.007.20095 (and earlier), 21.007.20096 (and earlier), 20.004.30015 (and earlier), and 17.011.30202 (and earlier) is affected by a use-after-free vulnerability in the processing of the GetURL function on a global object window that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

References