LiveBreach Intelligence: data breaches, leaks & ransomware, tracked as they surfaceOngoing protection: GalaxyWarden →
Recent BreachesData breach tracker

CVE-2021-28550: Adobe Acrobat and Reader Use-After-Free Vulnerability

RBRecent Breaches Vulnerability Intelligence·Nov 3, 2021
High⚠ Actively exploited (CISA KEV)
High
Severity
Active
CISA KEV
No
Ransomware use
Nov 17, 2021
Patch deadline
⚠ Exploited in the wild. CISA added CVE-2021-28550 to its Known Exploited Vulnerabilities catalog on Nov 3, 2021, with a federal patch deadline of Nov 17, 2021 — meaning attackers are actively using it. If you run the affected software, patch it immediately.

Adobe Acrobat and Reader contains a use-after-free vulnerability that could allow an unauthenticated attacker to achieve code execution in the context of the current user.

CVE-2021-28550 is a use-after-free vulnerability in Adobe Acrobat and Reader. According to CISA, an unauthenticated attacker could abuse it to achieve code execution in the context of the current user. For IT and security teams, that means a malicious PDF or related document opened by a user could lead to attacker-controlled code running with that user’s privileges, which is why prompt inventory and patching matter.

Public detail beyond the CISA summary and the CWE classification is limited here; confirm exact affected builds, fixed versions, and any configuration notes directly against the vendor advisory before acting.

How it works

This issue is classed as CWE-416 (use-after-free). In that weakness class, the application frees a block of memory but later continues to use a pointer to it. If an attacker can influence what occupies that memory afterward, they may corrupt program state or redirect execution.

In products like Acrobat and Reader, the typical abuse path for this class is a crafted document that triggers the flawed code path when the file is opened or processed. CISA states the outcome can be code execution in the context of the current user; the attacker does not need to authenticate to the application itself. Exact trigger conditions, heap layout requirements, and exploit mechanics are not provided in the given facts—treat any public proof-of-concept claims cautiously and validate behavior only in isolated lab environments against vendor guidance.

Am I affected? How to find it in your systems

Adobe Acrobat and Reader are commonly installed on end-user Windows and macOS workstations, VDI images, and sometimes on shared or kiosk systems used to view PDFs. They may also appear in automated document-processing pipelines if those pipelines shell out to the full reader rather than a headless library.

How to remediate

Patch first. CISA’s required action is to apply updates per vendor instructions. Obtain the fixed packages from Adobe’s official channels, validate hashes or signatures per your change process, and deploy to all inventoried Acrobat and Reader instances.

If you can't patch immediately

Compensating controls reduce—but do not eliminate—risk until the vendor update is applied.

If your data may have been exposed

Actively exploited vulnerabilities of this type can lead to workstation compromise and follow-on data theft, even when ransomware use is not documented for the CVE. If you have indicators that a malicious document was opened on an unpatched system, isolate the host, preserve memory and disk evidence, rotate credentials accessible from that user context, and begin incident response per your playbooks. As a supplementary check, individuals can run a free exposure scan of their email addresses against known breach datasets to see whether their identities already appear in public breach corpora.

AICompiled with AI assistance from public sources and published under our editorial standards.

Details

AffectedAdobe · Acrobat and Reader
WeaknessCWE-416
Added to CISA KEVNov 3, 2021
Federal patch deadlineNov 17, 2021
Known ransomware useNot documented
Check if your data is exposed →

Official records: NVD · CISA KEV

← All actively-exploited vulnerabilities