Type confusion in Adobe Reader and Adobe Acrobat - CVE-2021-35986
Published: July 13, 2021 / Updated: October 13, 2021
Vulnerability details
The vulnerability allows a remote attacker to compromise the affected system
The vulnerability exists due to a boundary condition within the getAnnots method when processing PDF files. A remote attacker can trick the victim to open a specially crafted PDF document, trigger a type confusion error and execute arbitrary code on the system.
Affected software
Adobe Acrobat
How to mitigate CVE-2021-35986
Adobe Acrobat - addressed in versions 17.011.30199, 20.004.30006, 21.005.20058