Security News > 2021 > May > Adobe fixes Reader zero-day vulnerability exploited in the wild

Adobe fixes Reader zero-day vulnerability exploited in the wild
2021-05-11 16:28

Adobe has released a massive Patch Tuesday security update release that fixes vulnerabilities in twelve different applications, including one actively exploited vulnerability Adobe Reader.

Of particular concern, Adobe warns that one of the Adobe Acrobat and Reader vulnerabilities tracked as CVE-2021-28550 has been exploited in the wild in limited attacks against Adobe Reader on Windows devices.

In total, there were 43 vulnerabilities fixed, not including dependencies in Adobe Experience Manager.

Out of all the Adobe security updates released today, Adobe Acrobat & Reader had the most fixes, with 14 vulnerabilities.

Adobe advises customers using vulnerable products to update to the latest versions as soon as possible to fix bugs that could lead to successful exploitation of unpatched installations.

This guidance is critical today, considering that the Adobe Acrobat & Reader CVE-2021-28550 vulnerability is known to be used in active attacks.


News URL

https://www.bleepingcomputer.com/news/security/adobe-fixes-reader-zero-day-vulnerability-exploited-in-the-wild/

Related Vulnerability

DATE CVE VULNERABILITY TITLE RISK
2021-09-02 CVE-2021-28550 Use After Free vulnerability in Adobe products
Acrobat Reader DC versions versions 2021.001.20150 (and earlier), 2020.001.30020 (and earlier) and 2017.011.30194 (and earlier) are affected by a Use After Free vulnerability.
network
low complexity
adobe CWE-416
8.8

Related vendor

VENDOR LAST 12M #/PRODUCTS LOW MEDIUM HIGH CRITICAL TOTAL VULNS
Adobe 167 66 2130 908 2113 5217