Adobe Readerí§Òâ´úÂëÖ´ÐÐ0dayÎó²î£¨CVE-2021-28550£©
Ðû²¼Ê±¼ä 2021-05-120x00 Îó²î¸ÅÊö
CVE ID | CVE-2021-28550 | ʱ ¼ä | 2021-05-12 |
Àà ÐÍ | ´úÂëÖ´ÐÐ | µÈ ¼¶ | ÑÏÖØ |
Ô¶³ÌʹÓà | Ó°Ïì¹æÄ£ | ||
PoC/EXP | δ¹ûÕæ | ÔÚҰʹÓà | ÊÇ |
0x01 Îó²îÏêÇé
2021Äê05ÔÂ11ÈÕ£¬£¬£¬£¬£¬AdobeÐû²¼Ç徲ͨ¸æ£¬£¬£¬£¬£¬ÐÞ¸´ÁËAdobe Reader for WindowsÖеÄÒ»¸öí§Òâ´úÂëÖ´ÐÐÎó²î£¨CVE-2021-28550£©£¬£¬£¬£¬£¬¹¥»÷Õß¿ÉÒÔͨ¹ýÏòÊÜÓ°ÏìµÄÓû§·¢ËͶñÒâÖÆ×÷µÄPDFÀ´Ê¹ÓôËÎó²î£¬£¬£¬£¬£¬×îÖÕ¿ÉÔì³Éí§Òâ´úÂëÖ´Ðв¢¿ØÖÆÖÕ¶Ë¡£¡£¡£¡£¡£¡£¡£ÏÖÔÚAdobeÔÝδÐû²¼´ËÎó²îµÄÊÖÒÕϸ½Ú£¬£¬£¬£¬£¬µ«¸ÃÎó²îÒÑÔÚҰʹÓᣡ£¡£¡£¡£¡£¡£
±ðµÄ£¬£¬£¬£¬£¬Adobe»¹ÐÞ¸´ÁËAcrobatºÍReaderÖÐµÄÆäËüÑÏÖØÎó²î£¬£¬£¬£¬£¬ÀÖ³ÉʹÓÃÕâЩÎó²îµÄ¹¥»÷ÕßÄܹ»ÔÚÄ¿µÄϵͳÖÐÖ´ÐÐí§Òâ´úÂ룺
2¸öÓÉÓÚUse After Freeµ¼ÖµÄí§Òâ´úÂëÖ´ÐеÄÎó²î£¨CVE-2021-28562ºÍCVE-2021-28553£©£»£»£»£»£»£»£»¿Éµ¼ÖÂí§Òâ´úÂëÖ´ÐеÄ4¸öÔ½½çдÈëÎó²î£¨CVE-2021-21044¡¢CVE-2021-21038¡¢CVE-2021-21086ºÍCVE-2021-28564£©£»£»£»£»£»£»£»
1¸ö¿Éµ¼ÖÂí§Òâ´úÂëÖ´ÐеÄÔ½½ç¶ÁÈ¡Îó²î£¨CVE-2021-28565£©ºÍ1¸ö¿Éµ¼ÖÂÄÚ´æ×ß©µÄÔ½½ç¶ÁÈ¡Îó²î£¨CVE-2021-28557£©£»£»£»£»£»£»£»
ÒÔ¼°1¸ö¿Éµ¼ÖÂí§Òâ´úÂëÖ´ÐеĻùÓڶѵĻº³åÇøÒç³öÎó²î£¨CVE-2021-28560£©¡£¡£¡£¡£¡£¡£¡£
Ó°Ïì¹æÄ£
Acrobat 2017 & Acrobat Reader 2017: <= 2017.011.30194£¨Windows & macOS£©
Acrobat 2020 & Acrobat Reader 2020: <= 2020.001.30020£¨Windows & macOS£©
Acrobat DC & Acrobat Reader DC: <= 2021.001.20149£¨macOS£©
Acrobat DC & Acrobat Reader DC: <= 2021.001.20150£¨Windows£©
0x02 ´¦Öóͷ£½¨Òé
ÏÖÔÚÏà¹ØÎó²îÒѾÐÞ¸´£¬£¬£¬£¬£¬½¨Ò龡¿ì¾ÙÐÐÇå¾²¸üС£¡£¡£¡£¡£¡£¡£
ÏÂÔØÁ´½Ó£º
https://get.adobe.com/cn/reader/
0x03 ²Î¿¼Á´½Ó
https://helpx.adobe.com/security/products/acrobat/apsb21-29.html
https://threatpost.com/adobe-zero-day-bug-acrobat-reader/166044/
https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-28850
0x04 ʱ¼äÏß
2021-05-11 AdobeÐû²¼Ç徲ͨ¸æ
2021-05-12 VSRCÐû²¼Ç徲ͨ¸æ
0x05 ¸½Â¼
CVSSÆÀ·Ö±ê×¼¹ÙÍø£ºhttp://www.first.org/cvss/