4.3

CVE-2021-44714

Adobe Acrobat Reader Missing Custom Protocols in Warning Message Prompts

Acrobat Reader DC version 21.007.20099 (and earlier), 20.004.30017 (and earlier) and 17.011.30204 (and earlier) are affected by a Violation of Secure Design Principles that could lead to a Security feature bypass. Acrobat Reader DC displays a warning message when a user clicks on a PDF file, which could be used by an attacker to mislead the user. In affected versions, this warning message does not include custom protocols when used by the sender. User interaction is required to abuse this vulnerability as they would need to click 'allow' on the warning message of a malicious file.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Adobe ≫ Acrobat Dc SwEdition continuous Version >= 15.008.20082 <= 21.007.20099
   Microsoft ≫ Windows Version -
Adobe ≫ Acrobat Reader Dc SwEdition continuous Version >= 15.008.20082 <= 21.007.20099
   Microsoft ≫ Windows Version -
Adobe ≫ Acrobat SwEdition classic Version >= 17.011.30059 <= 17.011.30204
   Apple ≫ macOS Version -
   Microsoft ≫ Windows Version -
Adobe ≫ Acrobat SwEdition classic Version >= 20.001.30005 <= 20.004.30017
   Apple ≫ macOS Version -
   Microsoft ≫ Windows Version -
Adobe ≫ Acrobat Reader SwEdition classic Version >= 17.011.30059 <= 17.011.30204
   Apple ≫ macOS Version -
   Microsoft ≫ Windows Version -
Adobe ≫ Acrobat Reader SwEdition classic Version >= 20.001.30005 <= 20.004.30017
   Apple ≫ macOS Version -
   Microsoft ≫ Windows Version -
Adobe ≫ Acrobat Dc SwEdition continuous Version >= 15.008.20082 <= 21.007.20099
   Apple ≫ macOS Version -
Adobe ≫ Acrobat Reader Dc SwEdition continuous Version >= 15.008.20082 <= 21.007.20099
   Apple ≫ macOS Version -
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 2.47% 0.825
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
NIST 3.3 1.8 1.4
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N
NIST 4.3 8.6 2.9
AV:N/AC:M/Au:N/C:P/I:N/A:N
Adobe 2.5 1 1.4
CVSS:3.1/AV:L/AC:H/PR:N/UI:R/S:U/C:L/I:N/A:N
CWE-657 Violation of Secure Design Principles

The product violates well-established principles for secure design.

https://helpx.adobe.com/security/products/acrobat/apsb22-01.html
Vendor Advisory