Adobe ReaderÈÎÒâ´úÂëÖ´ÐÐ0day©¶´£¨CVE-2021-28550£©
Ðû²¼Ê±¼ä 2021-05-120x00 ©¶´¸ÅÊö
CVE ID | CVE-2021-28550 | ʱ ¼ä | 2021-05-12 |
Àà ÐÍ | ´úÂëÖ´ÐÐ | µÈ ¼¶ | ÑÏÖØ |
Ô¶³ÌÀûÓà | Ó°Ï췶Χ | ||
PoC/EXP | δ¹ûÈ» | ÔÚÒ°ÀûÓà | ÊÇ |
0x01 ©¶´ÏêÇé
2021Äê05ÔÂ11ÈÕ£¬AdobeÐû²¼Äþ¾²Í¨¸æ£¬ÐÞ¸´ÁËAdobe Reader for WindowsÖеÄÒ»¸öÈÎÒâ´úÂëÖ´ÐЩ¶´£¨CVE-2021-28550£©£¬¹¥»÷Õß¿ÉÒÔͨ¹ýÏòÊÜÓ°ÏìµÄÓû§·¢ËͶñÒâÖÆ×÷µÄPDFÀ´ÀûÓôË©¶´£¬×îÖÕ¿ÉÔì³ÉÈÎÒâ´úÂëÖ´Ðв¢¿ØÖÆÖÕ¶Ë¡£Ä¿Ç°AdobeÔÝδÐû²¼´Ë©¶´µÄ¼¼Êõϸ½Ú£¬µ«¸Ã©¶´ÒÑÔÚÒ°ÀûÓá£
´ËÍ⣬Adobe»¹ÐÞ¸´ÁËAcrobatºÍReaderÖÐµÄÆäËüÑÏÖØÂ©¶´£¬ÀÖ³ÉÀûÓÃÕâЩ©¶´µÄ¹¥»÷ÕßÄܹ»ÔÚÄ¿±êϵͳÖÐÖ´ÐÐÈÎÒâ´úÂ룺
2¸öÓÉÓÚUse After Freeµ¼ÖµÄÈÎÒâ´úÂëÖ´ÐеÄ©¶´£¨CVE-2021-28562ºÍCVE-2021-28553£©£»¿Éµ¼ÖÂÈÎÒâ´úÂëÖ´ÐеÄ4¸öÔ½½çдÈë©¶´£¨CVE-2021-21044¡¢CVE-2021-21038¡¢CVE-2021-21086ºÍCVE-2021-28564£©£»
1¸ö¿Éµ¼ÖÂÈÎÒâ´úÂëÖ´ÐеÄÔ½½ç¶Áȡ©¶´£¨CVE-2021-28565£©ºÍ1¸ö¿Éµ¼ÖÂÄÚ´æÐ¹Â©µÄÔ½½ç¶Áȡ©¶´£¨CVE-2021-28557£©£»
ÒÔ¼°1¸ö¿Éµ¼ÖÂÈÎÒâ´úÂëÖ´ÐеĻùÓڶѵĻº³åÇøÒç³ö©¶´£¨CVE-2021-28560£©¡£
Ó°Ï췶Χ
Acrobat 2017 & Acrobat Reader 2017: <= 2017.011.30194£¨Windows & macOS£©
Acrobat 2020 & Acrobat Reader 2020: <= 2020.001.30020£¨Windows & macOS£©
Acrobat DC & Acrobat Reader DC: <= 2021.001.20149£¨macOS£©
Acrobat DC & Acrobat Reader DC: <= 2021.001.20150£¨Windows£©
0x02 ´¦Öý¨Òé
ĿǰÏà¹ØÂ©¶´ÒѾÐÞ¸´£¬½¨Ò龡¿ì½øÐÐÄþ¾²¸üС£
ÏÂÔØÁ´½Ó£º
https://get.adobe.com/cn/reader/
0x03 ²Î¿¼Á´½Ó
https://helpx.adobe.com/security/products/acrobat/apsb21-29.html
https://threatpost.com/adobe-zero-day-bug-acrobat-reader/166044/
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-28850
0x04 ʱ¼äÏß
2021-05-11 AdobeÐû²¼Äþ¾²Í¨¸æ
2021-05-12 VSRCÐû²¼Äþ¾²Í¨¸æ
0x05 ¸½Â¼
CVSSÆÀ·Ö³ß¶È¹ÙÍø£ºhttp://www.first.org/cvss/