vciy

Adobe Acrobat Reader: 26 records in one advisory

26 records announced together, published between 2022-01-14 and 2022-03-18, every one of them citing the same advisory.

The advisory

Every record in this batch cites https://helpx.adobe.com/security/products/acrobat/apsb22-01.html. That is the CNA's own reference, held in the index, and it is why these records are on one page.

What the records offer

No record in this batch publishes a fixed version in held sources.

No record in this batch is listed by CISA in held sources.

4 of 26 records name something of its own. For the other 22, held sources say the same thing about each.

Most commonly mapped weakness across the batch: CWE-416 Use After Free (CWE-416).

What this page does not cover

This batch is 26 of the 28 records that cite the same advisory. The other 2 are different findings announced alongside it.

None of those 2 is grouped with any other. Each one has its own record page and nothing else.

The batch is what one advisory announced. It is not every record sharing this weakness, this product or this mechanism, and nothing here is scoped to any estate.

What this batch was researched, not held

Four of these Acrobat records were bought on a contest stage three months before the fix

Adobe's January 2022 Acrobat and Reader update looks ordinary until you read where four of its entries came from. Security Affairs reports that CVE-2021-44704, CVE-2021-44705, CVE-2021-44706 and CVE-2021-44707 were credited to entrants in the Chinese Tianfu Cup hacking contest, and that the people who demonstrated the Reader exploits there earned 150,000 dollars between them. A contest entry is a working exploit shown on stage, not a bug report, so those four were already proven to work months before the update shipped. The bulletin also did not stop growing when it was published. Our index holds 26 records naming it, published between 14 January 2022 and 18 March 2022, which is why some of these records carry 2022 identifiers and dates two months after patch day.

A record in this batch may be an exploit that was demonstrated working on a stage, or an ordinary report, and only the credit line separates them. They share an update, not a flaw. Four of the 26 records here are the ones Security Affairs names as contest entries.

2021-10-01The Tianfu Cup runs in China; Security Affairs reports that the Reader demonstrations earned 150,000 dollars in total
2022-01-14The first records naming this bulletin reach the CVE list, among them the four credited to contest entrants
2022-03-18The last record naming this bulletin reaches the CVE list, two months after the update

Nobody publishes what the contest entrants actually did. Adobe does not say which of the four chained a sandbox escape, the contest does not publish its exploit write-ups, and no source gives a report date for any single entry, so the time between someone demonstrating one of these and Adobe fixing it is not knowable from anything here. The Tianfu Cup does not name which team took which finding either, so the four cannot be told apart by who brought them.

Written from securityweek.com, securityaffairs.com, cveawg.mitre.org, helpx.adobe.com. Reviewed for whether every claim traces to one of them, by two independent graders, citation support 4.44 of 5, uniqueness 4 of 5. Stated at high confidence. Nothing in this box is a value the index holds, and none of it opens a receipt.

Listed for shared announcement, not shared vulnerability. Each record here is its own finding with its own page, and fixing one does not address another.

CVE-2021-44701Adobe Acrobat Reader DC AcroForm Use-After-Free Remote Code Execution VulnerabilityCWE-416 Use After Free (CWE-416)
CVE-2021-44703Adobe Acrobat Pro DC Stack Overflow Vulnerability Arbitrary code executionCWE-121 Stack-based Buffer Overflow (CWE-121)
CVE-2021-44704Adobe Acrobat Reader Use-After-Free could lead to Arbitrary code executionCWE-416 Use After Free (CWE-416)
CVE-2021-44705Adobe Acrobat Reader Use-After-Free could lead to Arbitrary code executionCWE-416 Use After Free (CWE-416)
CVE-2021-44706Adobe Acrobat Reader Collab.registerReview Use-After-Free Remote Execution VulnerabilityCWE-416 Use After Free (CWE-416)
CVE-2021-44707Adobe Acrobat Reader DC OTF Font Parsing Out-Of-Bounds Write Remote Code Execution VulnerabilityCWE-787 Out-of-bounds Write (CWE-787)
CVE-2021-44708Adobe Acrobat Pro DC Heap Overflow could lead to Arbitrary code executionCWE-122 Heap-based Buffer Overflow (CWE-122)
CVE-2021-44709Adobe Acrobat Pro DC Heap Overflow Vulnerability could lead to Arbitrary code executionCWE-122 Heap-based Buffer Overflow (CWE-122)
CVE-2021-44710Adobe Acrobat Reader Use-after-free could lead to Arbitrary code executionCWE-416 Use After Free (CWE-416)
CVE-2021-44711Adobe Acrobat Reader DC annotation gestures integer overflow vulnerabilityCWE-190 Integer Overflow or Wraparound (CWE-190)
CVE-2021-44712Adobe Acrobat Reader Memory Corruption could lead to Application denial-of-serviceCWE-788 Access of Memory Location After End of…
CVE-2021-44713Adobe Acrobat Reader DC Use After Free could lead to Application denial-of-serviceCWE-416 Use After Free (CWE-416)
CVE-2021-44714Adobe Acrobat Reader Missing Custom Protocols in Warning Message PromptsCWE-657 Violation of Secure Design Principles…
CVE-2021-44715Adobe Acrobat Reader DC Out-of-Bounds Read Information Disclosure VulnerabilityCWE-125 Out-of-bounds Read (CWE-125)
CVE-2021-44740Adobe Acrobat Pro DC NULL Pointer Dereference could lead to Application-denial-of-serviceCWE-476 NULL Pointer Dereference (CWE-476)
CVE-2021-44741Adobe Acrobat Pro DC NULL Pointer Dereference could lead to Application-denial-of-serviceCWE-476 NULL Pointer Dereference (CWE-476)
CVE-2021-44742Adobe Reader Out-of-bounds Read Remote Code Execution VulnerabilityCWE-125 Out-of-bounds Read (CWE-125)
CVE-2021-45060Adobe Acrobat Reader DC TTF Font Parsing Out-Of-Bounds Read Remote Code Execution VulnerabilityCWE-125 Out-of-bounds Read (CWE-125)
CVE-2021-45061Adobe Acrobat Reader DC Font Parsing Out-Of-Bounds Write Remote Code Execution VulnerabilityCWE-787 Out-of-bounds Write (CWE-787)
CVE-2021-45062Adobe Acrobat Reader DC Font Parsing Use-After-Free Remote Code Execution VulnerabilityCWE-416 Use After Free (CWE-416)
CVE-2021-45063Adobe Acrobat Reader DC JP2 File Parsing Use-After-Free Information Disclosure VulnerabilityCWE-416 Use After Free (CWE-416)
CVE-2021-45064Adobe Acrobat Reader DC AcroForm Use-After-Free Remote Code Execution VulnerabilityCWE-416 Use After Free (CWE-416)
CVE-2021-45067Adobe Acrobat Reader Memory Corruption could lead to Information DisclosureCWE-788 Access of Memory Location After End of…
CVE-2021-45068Adobe Acrobat Reader DC Font Parsing Out-Of-Bounds Write Remote Code Execution VulnerabilityCWE-787 Out-of-bounds Write (CWE-787)
CVE-2022-24091Adobe Acrobat Reader DC Font Parsing Out-Of-Bounds Write Remote Code Execution VulnerabilityCWE-787 Out-of-bounds Write (CWE-787)
CVE-2022-24092Adobe Acrobat Reader DC Font Parsing Out-Of-Bounds Write Remote Code Execution VulnerabilityCWE-787 Out-of-bounds Write (CWE-787)

26 records, read from the index as it stood on 2026-09-20. Every row opens the record it names, and every value on that record opens its own receipt.

Everything on this page is free. Public data. Withholding it protects nothing.