CVE-2021-44714 Details
Description
Acrobat Reader DC version 21.007.20099 (and earlier), 20.004.30017 (and earlier) and 17.011.30204 (and earlier) are affected by a Violation of Secure Design Principles that could lead to a Security feature bypass. Acrobat Reader DC displays a warning message when a user clicks on a PDF file, which could be used by an attacker to mislead the user. In affected versions, this warning message does not include custom protocols when used by the sender. User interaction is required to abuse this vulnerability as they would need to click 'allow' on the warning message of a malicious file.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
No SSVC data is available for this CVE.
References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://helpx.adobe.com/security/products/acrobat/apsb22-01.html | CVE | Vendor Advisory |
| https://helpx.adobe.com/security/products/acrobat/apsb22-01.html | [email protected] | Vendor Advisory |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| NVD-CWE-Other | Weakness Not in a Standard CWE Category | [email protected] |
| CWE-657 | Violation of Secure Design Principles | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| adobe acrobat dc | >= 15.008.20082, <= 21.007.20099 |
CPE
Remediation
| |
| adobe acrobat reader dc | >= 15.008.20082, <= 21.007.20099 |
CPE
Remediation
| |
| microsoft windows | All versions |
CPE
Remediation
| |
| adobe acrobat | >= 17.011.30059, <= 17.011.30204 >= 20.001.30005, <= 20.004.30017 |
CPE
Remediation
| |
| adobe acrobat reader | >= 17.011.30059, <= 17.011.30204 >= 20.001.30005, <= 20.004.30017 |
CPE
Remediation
| |
| apple macos | All versions |
CPE
Remediation
| |
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Nov 21, 2024 | CVE Modified | CVE |
| May 14, 2024 | CVE Modified | [email protected] |
| Jan 21, 2022 | Initial Analysis | [email protected] |