Netskope Threat Labs

FILE-PDF Adobe Acrobat PDF thermometer use-after-free attempt

IPS-SWG

1 SID: 59105

First seen
July 2025
Last seen
July 2025

Detects a PDF exploiting CVE-2021-28640, a use-after-free in Adobe Acrobat's progress indicator interface that can allow code execution. The rule matches the scripted indicator and document close sequencing that public exploits use to free the object while it remains in use.