PT-2022-3634 · Adobe · Acrobat Reader

Published

2022-07-12

·

Updated

2024-06-08

·

CVE-2022-34233

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Adobe Acrobat Reader versions 22.001.20142 and earlier Adobe Acrobat Reader versions 20.005.30334 and earlier Adobe Acrobat Reader versions 17.012.30229 and earlier
Description A use-after-free vulnerability could lead to disclosure of sensitive memory, allowing an attacker to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction, where a victim must open a malicious file. This vulnerability is related to the use of memory after it has been freed, which may allow an attacker to gain unauthorized access to protected information.
Recommendations For Adobe Acrobat Reader versions 22.001.20142 and earlier, update to a version later than 22.001.20142 to resolve the issue. For Adobe Acrobat Reader versions 20.005.30334 and earlier, update to a version later than 20.005.30334 to resolve the issue. For Adobe Acrobat Reader versions 17.012.30229 and earlier, update to a version later than 17.012.30229 to resolve the issue. As a temporary workaround, consider avoiding the use of Adobe Acrobat Reader to open files from untrusted sources until a patch is available.

Fix

Use After Free

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2022-04419
CVE-2022-34233
ZDI-22-985

Affected Products

Acrobat Reader