Rewterz Threat Advisory – CVE-2021-1287 – Cisco Small Business RV132W and RV134W Routers Management Interface Vulnerability
March 19, 2021Rewterz Threat Advisory – CVE-2021-3428 – Linux Kernel denial of service
March 19, 2021Rewterz Threat Advisory – CVE-2021-1287 – Cisco Small Business RV132W and RV134W Routers Management Interface Vulnerability
March 19, 2021Rewterz Threat Advisory – CVE-2021-3428 – Linux Kernel denial of service
March 19, 2021Severity
High
Analysis Summary
CVE-2021-21089
Adobe Acrobat and Adobe Reader could allow a remote attacker to gain elevated privileges on the system, caused by an out-of-bounds read error within the handling of URIs by weblink.api. By persuading a victim to open a specially-crafted document, a remote attacker could exploit this vulnerability to execute arbitrary code on the system with the privileges of the victim or cause the application to crash.
CVE-2021-21088
Adobe Acrobat and Adobe Reader could allow a remote attacker to execute arbitrary code on the system, caused by a use-after-free error within the colorConvertPage method. By persuading a victim to open a specially-crafted document, a remote attacker could exploit this vulnerability to execute arbitrary code on the system with the privileges of the victim or cause the application to crash.
CVE-2021-21086
Adobe Acrobat and Adobe Reader could allow a remote attacker to execute arbitrary code on the system, caused by an out-of-bounds write error. By persuading a victim to open a specially-crafted document, a remote attacker could exploit this vulnerability to execute arbitrary code on the system with the privileges of the victim or cause the application to crash.
Impact
- Gain Privileges
- Arbitrary code execution
Affected Vendors
Adobe
Affected Products
- Adobe Acrobat 2017 2017.011.30188
- Adobe Acrobat 2020 20.001.30018
- Adobe Acrobat 2020 20.001.30018
Remediation
Refer to Adobe Security Bulletin APSB21-09 for patch, upgrade or suggested workaround information.