Netskope Threat Labs

FILE-PDF Adobe Acrobat PDF buttonGetIcon use-after-free attempt

IPS-SWG

1 SID: 59084

First seen
July 2025
Last seen
July 2025

Detects a PDF exploiting CVE-2021-39836, a use-after-free in Adobe Acrobat's form button icon handling that can allow code execution. The rule matches the icon query calls that public exploits use to free button objects while they remain in use.