Acrobat Reader DC ActiveX Control versions 2021.005.20060, 2020.004.30006, and 2017.011.30199 have an Information Disclosure vulnerability. Learn the impact, technical details, and mitigation steps.
Adobe Acrobat Reader DC NTLMv2 SSO Information Disclosure via LoadFile
Understanding CVE-2021-39856
Acrobat Reader DC ActiveX Control versions 2021.005.20060 (and earlier), 2020.004.30006 (and earlier), and 2017.011.30199 (and earlier) are affected by an Information Disclosure vulnerability. An unauthenticated attacker could leverage this vulnerability to obtain NTLMv2 credentials. Exploitation of this issue requires user interaction in that a victim must visit an attacker controlled web page.
What is CVE-2021-39856?
The Impact of CVE-2021-39856
Technical Details of CVE-2021-39856
Adobe Acrobat Reader DC ActiveX Control is affected by an information disclosure vulnerability.
Vulnerability Description
Affected Systems and Versions
Exploitation Mechanism
Mitigation and Prevention
It's crucial to take immediate steps and implement long-term security measures to mitigate the risk of this vulnerability.
Immediate Steps to Take
Long-Term Security Practices
Patching and Updates