NULL pointer dereference in Adobe Reader and Adobe Acrobat - CVE-2021-44741
Published: January 11, 2022
Vulnerability identifier: #VU59447
CSH Severity: Low
CVSS v4: 4.6 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:N/VI:N/VA:L/SC:N/SI:N/SA:N]
CVE-ID: CVE-2021-44741
CWE-ID: CWE-476
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to a NULL pointer dereference error. A remote attacker can trick the victim to open a specially crafted PDF file and perform a denial of service (DoS) attack.
Affected software
Adobe Reader
Adobe Acrobat
Foxit PDF Reader for Windows
Foxit PDF Editor (formerly Foxit PhantomPDF)
Adobe Acrobat
Foxit PDF Reader for Windows
Foxit PDF Editor (formerly Foxit PhantomPDF)
How to mitigate CVE-2021-44741
Install updates from vendor's website.
Adobe Reader - addressed in versions 17.011.30207, 20.004.30020, 21.011.20039
Adobe Acrobat - addressed in versions 17.011.30207, 20.004.30020, 21.011.20039
Foxit PDF Reader for Windows - update to 11.2.1.53537
Foxit PDF Editor (formerly Foxit PhantomPDF) - update to 11.2.1.53537
Adobe Acrobat - addressed in versions 17.011.30207, 20.004.30020, 21.011.20039
Foxit PDF Reader for Windows - update to 11.2.1.53537
Foxit PDF Editor (formerly Foxit PhantomPDF) - update to 11.2.1.53537