vciy

Adobe Acrobat Reader: 25 records in one advisory

25 records announced together, published between 2021-09-29 and 2023-09-06, every one of them citing the same advisory.

The advisory

Every record in this batch cites https://helpx.adobe.com/security/products/acrobat/apsb21-55.html. That is the CNA's own reference, held in the index, and it is why these records are on one page.

What the records offer

No record in this batch publishes a fixed version in held sources.

No record in this batch is listed by CISA in held sources.

13 of 25 records name something of its own. For the other 12, held sources say the same thing about each.

Most commonly mapped weakness across the batch: CWE-416 Use After Free (CWE-416).

What this page does not cover

This batch is 25 of the 28 records that cite the same advisory. The other 3 are different findings announced alongside it.

None of those 3 is grouped with any other. Each one has its own record page and nothing else.

The batch is what one advisory announced. It is not every record sharing this weakness, this product or this mechanism, and nothing here is scoped to any estate.

What this batch was researched, not held

One fix in this Adobe update existed only because the June fix locked the wrong fields

APSB21-55 is Adobe's Acrobat and Reader update of 14 September 2021, for Acrobat and Reader DC at 2021.005.20060 and earlier, the 2020 track at 2020.004.30006 and earlier and the 2017 track at 2017.011.30199 and earlier. One of its entries has a public account of where it came from, and it is not an independent discovery. Writing for Trend Micro's Zero Day Initiative in October 2021, Mark Vincent Yason explained that he had found an earlier bug, CVE-2021-28632, by fuzzing. It was a use-after-free in the C++ objects that represent interactive form fields inside Adobe's AcroForm module, where locking a field failed to lock the fields beneath it, so a callback could free a child that was still in use. Adobe fixed that one in June 2021 by adding a call that locks the field's immediate descendants. Yason read the patch, noticed it locked only one level down, and reached the same bug through a grandchild field. That bypass is CVE-2021-39840, which Adobe fixed here in September. Of the 27 identifiers whose public records point at this bulletin, the two largest groups are 8 use-after-free and 7 null pointer dereference, with 4 out-of-bounds read, 3 out-of-bounds write and 3 information exposure behind them.

These identifiers were announced on one day by one vendor and came from several unrelated reporters, so the record you are reading is separate from the rest even where two sit in the same part of the code. The one exception is documented by the researcher himself: CVE-2021-39840 exists because the earlier fix for CVE-2021-28632 was incomplete, so having installed the June 2021 update did not cover it.

2021-09-14Adobe publishes APSB21-55 for Acrobat and Reader.
2021-09-29The public record for CVE-2021-39840 is published, describing a use-after-free when processing AcroForms.
2021-10-21Zero Day Initiative publishes Yason's write-up showing CVE-2021-39840 is a bypass of the June fix for CVE-2021-28632.

Adobe gives no report date, no affected function and no reproduction for any entry, so the gap between discovery and the 14 September announcement is unknown, and the bulletin says nothing about whether any of these were used in attacks. Only the one Yason wrote up publicly has a known root cause; for the rest the public record gives a weakness class and no code.

Written from thezdi.com, services.nvd.nist.gov, helpx.adobe.com. Reviewed for whether every claim traces to one of them, by two independent graders, citation support 4.44 of 5, uniqueness 4 of 5. Stated at high confidence. Nothing in this box is a value the index holds, and none of it opens a receipt.

Listed for shared announcement, not shared vulnerability. Each record here is its own finding with its own page, and fixing one does not address another.

CVE-2021-35982Adobe Reader DC Windows Installer Uncontrolled Search Path element could lead to Arbitrary Code ExecutionCWE-427 Uncontrolled Search Path Element…
CVE-2021-39836Adobe Acrobat Reader DC AcroForm buttonGetIcon Use-After-Free Remote Code Execution VulnerabilityCWE-416 Use After Free (CWE-416)
CVE-2021-39837Adobe Acrobat Reader DC AcroForm deleteItemAt Use-After-Free Remote Code Execution VulnerabilityCWE-416 Use After Free (CWE-416)
CVE-2021-39838Adobe Acrobat Reader DC AcroForm buttonGetCaption Use-After-Free Remote Code Execution VulnerabilityCWE-416 Use After Free (CWE-416)
CVE-2021-39839Adobe Acrobat Reader DC AcroForm getItemAt Use-After-Free Remote Code Execution VulnerabilityCWE-416 Use After Free (CWE-416)
CVE-2021-39840Adobe Acrobat Reader DC AcroForm Field Use-After-Free Remote Code Execution VulnerabilityCWE-416 Use After Free (CWE-416)
CVE-2021-39841Adobe Acrobat Pro DC DocMedia Type Confusion Remote Code Execution VulnerabilityCWE-843 Access of Resource Using Incompatible…
CVE-2021-39842Adobe Acrobat Reader DC messageHandler.OnMessage Use-After-Free VulnerabilityCWE-416 Use After Free (CWE-416)
CVE-2021-39843Adobe Acrobat Reader XObject Out-of-Bound Write VulnerabilityCWE-787 Out-of-bounds Write (CWE-787)
CVE-2021-39844Adobe Acrobat Reader CalRGB Out-of-Bounds Read VulnerabilityCWE-125 Out-of-bounds Read (CWE-125)
CVE-2021-39845Adobe Acrobat Reader Page Tree Node Recursive Stack OverflowCWE-121 Stack-based Buffer Overflow (CWE-121)
CVE-2021-39846Adobe Acrobat Reader /Parent Property Recursive Stack OverflowCWE-121 Stack-based Buffer Overflow (CWE-121)
CVE-2021-39849Adobe Acrobat Reader DC Null Pointer Dereference Could Lead To Application Denial-of-ServiceCWE-476 NULL Pointer Dereference (CWE-476)
CVE-2021-39850Adobe Acrobat Reader DC Null Pointer Dereference Could Lead To Application Denial-of-ServiceCWE-476 NULL Pointer Dereference (CWE-476)
CVE-2021-39851Adobe Acrobat Reader DC Null Pointer Dereference Could Lead To Application Denial-of-ServiceCWE-476 NULL Pointer Dereference (CWE-476)
CVE-2021-39852Adobe Acrobat Reader DC Null Pointer Dereference Could Lead To Application Denial-of-ServiceCWE-476 NULL Pointer Dereference (CWE-476)
CVE-2021-39853Adobe Acrobat Reader DC Null Pointer Dereference Could Lead To Application Denial-of-ServiceCWE-476 NULL Pointer Dereference (CWE-476)
CVE-2021-39854Adobe Acrobat Reader DC Null Pointer Dereference Could Lead To Application Denial-of-ServiceCWE-476 NULL Pointer Dereference (CWE-476)
CVE-2021-39857Adobe Acrobat Reader DC Information Disclosure via ActiveX LoadFileCWE-200 Information Exposure (CWE-200)
CVE-2021-39858Adobe Acrobat Pro DC PostScript File Parsing Out-Of-Bounds Read Information Disclosure VulnerabilityCWE-125 Out-of-bounds Read (CWE-125)
CVE-2021-39859Use After Free Adobe Acrobat Pro DC [HB-21-0339]CWE-416 Use After Free (CWE-416)
CVE-2021-39861Adobe Acrobat Reader DC Catalog Plugin Out-of-Bounds Read BugCWE-125 Out-of-bounds Read (CWE-125)
CVE-2021-39863Adobe Acrobat Reader DC Heap-based Buffer Overflow Vulnerability Could Lead To Arbitrary Code ExecutionCWE-122 Heap-based Buffer Overflow (CWE-122)
CVE-2021-40725Adobe Acrobat Reader DC AcroForm listbox Use-After-Free Remote Code Execution VulnerabilityCWE-416 Use After Free (CWE-416)
CVE-2021-40726Adobe Acrobat Reader DC AcroForm Field Use-After-Free Remote Code Execution VulnerabilityCWE-416 Use After Free (CWE-416)

25 records, read from the index as it stood on 2026-09-20. Every row opens the record it names, and every value on that record opens its own receipt.

Everything on this page is free. Public data. Withholding it protects nothing.