Adobe ReaderËÁÒâ´úÂëÖ´ÐÐ0day·ì϶£¨CVE-2021-28550£©

°ä²¼¹¦·ò 2021-05-12

0x00 ·ì϶¸ÅÊö

CVE   ID

CVE-2021-28550

ʱ    ¼ä

2021-05-12

Àà    ÐÍ

´úÂëÖ´ÐÐ

µÈ    ¼¶

ÑϳÁ

Ô¶³ÌÀûÓÃ


Ó°ÏìÁìÓò


PoC/EXP

δ¹«¿ª

ÔÚÒ°ÀûÓÃ

ÊÇ

 

0x01 ·ì϶ÏêÇé

image.png

 

2021Äê05ÔÂ11ÈÕ£¬Adobe°ä²¼°²È«²¼¸æ£¬½¨¸´ÁËAdobe Reader for WindowsÖеÄÒ»¸öËÁÒâ´úÂëÖ´Ðзì϶£¨CVE-2021-28550£©£¬¹¥»÷ÕßÄܹ»Í¨¹ýÏòÊÜÓ°ÏìµÄÓû§·¢ËͶñÒâÔì×÷µÄPDFÀ´ÀûÓô˷ì϶£¬×îÖÕ¿ÉÔì³ÉËÁÒâ´úÂëÖ´Ðв¢½ÚÔìÖÕ¶Ë¡£Ä¿Ç°AdobeÔÝδ°ä²¼´Ë·ì϶µÄ¼¼Êõϸ½Ú£¬µ«¸Ã·ì϶ÒÑÔÚÒ°ÀûÓá£

´Ë±í£¬Adobe»¹½¨¸´ÁËAcrobatºÍReaderÖÐµÄÆäËüÑϳÁ·ì϶£¬³É¹¦ÀûÓÃÕâЩ·ì϶µÄ¹¥»÷Õß¿ÉÄÜÔÚÖ¸±êϵͳÖÐÖ´ÐÐËÁÒâ´úÂ룺

2¸öÓÉÓÚUse After Freeµ¼ÖµÄËÁÒâ´úÂëÖ´Ðеķì϶£¨CVE-2021-28562ºÍCVE-2021-28553£©£»¿Éµ¼ÖÂËÁÒâ´úÂëÖ´ÐеÄ4¸öÔ½½çдÈë·ì϶£¨CVE-2021-21044¡¢CVE-2021-21038¡¢CVE-2021-21086ºÍCVE-2021-28564£©£»

1¸ö¿Éµ¼ÖÂËÁÒâ´úÂëÖ´ÐеÄÔ½½ç¶ÁÈ¡·ì϶£¨CVE-2021-28565£©ºÍ1¸ö¿Éµ¼ÖÂÄÚ´æÐ¹Â©µÄÔ½½ç¶ÁÈ¡·ì϶£¨CVE-2021-28557£©£»

ÒÔ¼°1¸ö¿Éµ¼ÖÂËÁÒâ´úÂëÖ´ÐеĻùÓڶѵĻº³åÇøÒç¶Âí½Å£¨CVE-2021-28560£©¡£

 

Ó°ÏìÁìÓò

Acrobat 2017 & Acrobat Reader 2017: <= 2017.011.30194£¨Windows & macOS£©

Acrobat 2020 & Acrobat Reader 2020: <= 2020.001.30020£¨Windows & macOS£©

Acrobat DC & Acrobat Reader DC: <= 2021.001.20149£¨macOS£©

Acrobat DC & Acrobat Reader DC: <= 2021.001.20150£¨Windows£©

 

0x02 ´ëÖý¨Òé

ĿǰÓйطì϶ÒѾ­½¨¸´£¬½¨Ò龡¿ì½øÐа²È«¸üС£

ÏÂÔØÁ´½Ó£º

https://get.adobe.com/cn/reader/

 

0x03 ²Î¿¼Á´½Ó

https://helpx.adobe.com/security/products/acrobat/apsb21-29.html

https://threatpost.com/adobe-zero-day-bug-acrobat-reader/166044/

https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2021-28850

 

0x04 ¹¦·òÏß

2021-05-11  Adobe°ä²¼°²È«²¼¸æ

2021-05-12  VSRC°ä²¼°²È«¹«¸æ

 

0x05 ¸½Â¼

 

CVSSÆÀ·Ö³ß¶È¹ÙÍø£ºhttp://www.first.org/cvss/

image.png