Adobe has released a security update to fix a vulnerability affecting Acrobat DC, Acrobat Reader DC, Acrobat 2020, Acrobat Reader 2020, Acrobat 2017, and Acrobat Reader 2017 , on both Windows and Mac .

The company said in a security bulletin that it has received reports of a new vulnerability that has been exploited in attacks (albeit limited) targeting Adobe Reader users on Windows.
See also: Adobe announces next generation of CDP platform
The vulnerability has been named CVE-2021-28550, and according to Adobe, its successful exploitation could lead to arbitrary code execution.
Cybersecurity experts, such as Shawn Smith from nVisium, have stated that arbitrary code execution is a serious threat that can cause quite a few problems.

Sean Nikkel, senior threat analyst at Digital Shadows, said that the use of malicious PDF files has been a key attack method for various state-sponsored hacking groups and other criminals for years. Criminals are taking advantage of the massive use of Adobe products in both the private and public sectors.
See also: Adobe Audition app is optimized for M1 Macs
Nikkel also said that attackers often send phishing emails with PDF attachments to entice users to download and open the files. Typically, hackers try to convince victims to open the document by saying it is something very important, such as a financial document, a news article, etc.
"In some cases, a would-be attacker could create a malicious website that also hosts infected PDF files," Nikkel said.
See also: iPhone: How to convert Notes to PDF [two ways]
“In general, PDF documents, which are often opened either through a browser or through a reader program such as Adobe Acrobat or Reader, can contain malicious Javascript or allow some other system interaction that allows code execution or other attacks, sometimes without the user's knowledge“.
Nikkel said that a huge increase in attacks with infected documents has been reported, and it is believed that the increase is largely due to remote working.
Source: ZDNet
