vciy

Adobe Acrobat Reader: 26 records in one advisory

26 records announced together, published between 2021-02-11 and 2023-09-07, every one of them citing the same advisory.

The advisory

Every record in this batch cites https://helpx.adobe.com/security/products/acrobat/apsb21-09.html. That is the CNA's own reference, held in the index, and it is why these records are on one page.

What the records offer

No record in this batch publishes a fixed version in held sources.

1 record is listed by CISA with a required action, which carries a federal remediation deadline on its own page.

10 of 26 records name something of its own. For the other 16, held sources say the same thing about each.

Most commonly mapped weakness across the batch: CWE-416 Use After Free (CWE-416).

What this page does not cover

This batch is 26 of the 29 records that cite the same advisory. The other 3 are different findings announced alongside it.

None of those 3 is grouped with any other. Each one has its own record page and nothing else.

The batch is what one advisory announced. It is not every record sharing this weakness, this product or this mechanism, and nothing here is scoped to any estate.

What this batch was researched, not held

The Acrobat fix that also closed a way to change a certified document

Adobe published this bulletin in February 2021 for Acrobat and Reader, and the records under it are not one kind of problem. Most describe memory faults in the code that opens a file. One, CVE-2021-21017, is a heap-based buffer overflow that lets someone who gets you to open a file run code as you, and CISA later added it to the catalogue of vulnerabilities known to have been exploited. Two others are not memory faults at all. CVE-2021-28545 and CVE-2021-28546 both say Acrobat Reader is missing support for an integrity check, so someone can change what a certified document says without the certification turning invalid. Four researchers at the Chair for Network and Data Security at Ruhr University Bochum, Simon Rohlmann, Vladislav Mladenov, Christian Mainka and Jorg Schwenk, published a report on attacks against PDF certification that names those two identifiers as the fixes Adobe shipped. Their report says they could change the visible content of a certified document in 15 of the 26 viewer applications they tested.

These were announced under one bulletin and they do not describe the same kind of harm. Some are about code running when a file is opened. Two are about a signed document surviving a change it should not survive. One of the 26 records in this group, CVE-2021-21017, is in the CISA catalogue of vulnerabilities known to have been exploited, and the other 25 are not.

2021-02-11CVE-2021-21017 reaches the CVE list, referencing this bulletin
2021-03-15The Ruhr University Bochum team publish version 2 of their report on attacks against PDF certification, naming CVE-2021-28545 and CVE-2021-28546 as…
2021-04-01CVE-2021-28545 and CVE-2021-28546 reach the CVE list, seven weeks after the bulletin, both referencing it
2021-11-03CISA adds CVE-2021-21017 to the catalogue of vulnerabilities known to have been exploited, with a fix-by date of 17 November 2021

Adobe's acknowledgements page is not readable to us, so for any single record here we cannot say who reported it. The only dates we hold are the days records reached the CVE list, and for this bulletin those run from February 2021 to September 2023, so nothing here tells you how long Adobe had a given report before the February 2021 update shipped.

Written from cveawg.mitre.org, cveawg.mitre.org, cveawg.mitre.org, pdf-insecurity.org, news.rub.de, cisa.gov, helpx.adobe.com. Reviewed for whether every claim traces to one of them, by two independent graders, citation support 4.44 of 5, uniqueness 4 of 5. Stated at high confidence. Nothing in this box is a value the index holds, and none of it opens a receipt.

Listed for shared announcement, not shared vulnerability. Each record here is its own finding with its own page, and fixing one does not address another.

CVE-2021-21017Acrobat Reader DC Heap-based Buffer Overflow Vulnerability Could Lead To Arbitrary Code ExecutionCWE-122 Heap-based Buffer Overflow (CWE-122)
CVE-2021-21021Acrobat Reader DC Use-After-Free Vulnerability Could Lead To Arbitrary Code ExecutionCWE-416 Use After Free (CWE-416)
CVE-2021-21028Acrobat Reader DC Use-After-Free Vulnerability Could Lead To Arbitrary Code ExecutionCWE-416 Use After Free (CWE-416)
CVE-2021-21033Acrobat Reader DC Use-After-Free Vulnerability Could Lead To Arbitrary Code ExecutionCWE-416 Use After Free (CWE-416)
CVE-2021-21034Acrobat Reader DC Out-Of-Bounds Read Information Disclosure VulnerabilityCWE-125 Out-of-bounds Read (CWE-125)
CVE-2021-21035Acrobat Reader DC Use-After-Free Vulnerability Could Lead To Arbitrary Code ExecutionCWE-416 Use After Free (CWE-416)
CVE-2021-21036Acrobat Reader DC Integer Overflow Vulnerability Could Lead To Arbitrary Code ExecutionCWE-190 Integer Overflow or Wraparound (CWE-190)
CVE-2021-21037Acrobat Reader DC Path Traversal Vulnerability Could Lead To Arbitrary Code ExecutionCWE-22 Improper Limitation of a Pathname to a…
CVE-2021-21038Acrobat Reader DC Out-Of-Bounds Write Vulnerability Could Lead To Arbitrary Code ExecutionCWE-787 Out-of-bounds Write (CWE-787)
CVE-2021-21039Acrobat Reader DC Use-After-Free Vulnerability Could Lead To Arbitrary Code ExecutionCWE-416 Use After Free (CWE-416)
CVE-2021-21040Acrobat Reader DC Use-After-Free Vulnerability Could Lead To Arbitrary Code ExecutionCWE-416 Use After Free (CWE-416)
CVE-2021-21041Acrobat Reader DC Use-After-Free Vulnerability Could Lead To Arbitrary Code ExecutionCWE-416 Use After Free (CWE-416)
CVE-2021-21044Acrobat Reader DC Out-Of-Bounds Write Vulnerability Could Lead To Arbitrary Code ExecutionCWE-787 Out-of-bounds Write (CWE-787)
CVE-2021-21045Acrobat Reader DC Improper Installer Access Control Vulnerability Could Lead To Privilege EscalationCWE-284 Improper Access Control (CWE-284)
CVE-2021-21046Acrobat Reader DC Buffer Overflow Vulnerability Could Lead To Arbitrary Code ExecutionCWE-787 Out-of-bounds Write (CWE-787)
CVE-2021-21057Acrobat Reader DC Invalid Memory Read Due To An Uninitialized PointerCWE-476 NULL Pointer Dereference (CWE-476)
CVE-2021-21058Acrobat Reader DC Memory Corruption Vulnerability Could Lead to Arbitrary Code ExecutionCWE-787 Out-of-bounds Write (CWE-787)
CVE-2021-21059Acrobat Reader DC Buffer Overflow Vulnerability Could Lead to Arbitrary Code ExecutionCWE-787 Out-of-bounds Write (CWE-787)
CVE-2021-21062Acrobat Reader DC Buffer Overflow Vulnerability Could Lead To Arbitrary Code ExecutionCWE-787 Out-of-bounds Write (CWE-787)
CVE-2021-21063Acrobat Reader DC Buffer Overflow Vulnerability Could Lead to Arbitrary Code ExecutionCWE-787 Out-of-bounds Write (CWE-787)
CVE-2021-21086Adobe Reader CoolType Arbitrary Stack ManipulationCWE-787 Out-of-bounds Write (CWE-787)
CVE-2021-21088Adobe Acrobat Pro DC Use-After-Free Remote Code Execution VulnerabilityCWE-416 Use After Free (CWE-416)
CVE-2021-21089Adobe Acrobat Reader DC URI Parsing Out-Of-Bounds ReadCWE-125 Out-of-bounds Read (CWE-125)
CVE-2021-28545Acrobat Reader DC Missing Support for Integrity CheckCWE-353 Missing Support for Integrity Check…
CVE-2021-28546Acrobat Reader DC Missing Support for Integrity CheckCWE-353 Missing Support for Integrity Check…
CVE-2021-40723Acrobat Reader DC Out-Of-Bounds Read Information Disclosure VulnerabilityCWE-125 Out-of-bounds Read (CWE-125)

26 records, read from the index as it stood on 2026-09-20. Every row opens the record it names, and every value on that record opens its own receipt.

Everything on this page is free. Public data. Withholding it protects nothing.