PT-2022-3686 · Adobe · Acrobat Reader

Published

2022-07-12

·

Updated

2022-07-21

·

CVE-2022-34234

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Adobe Acrobat Reader versions 22.001.20142 and earlier Adobe Acrobat Reader versions 20.005.30334 and earlier Adobe Acrobat Reader versions 17.012.30229 and earlier
Description The issue is related to a use-after-free vulnerability in Adobe Acrobat and Reader, which could lead to the disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as Address Space Layout Randomization (ASLR). Exploitation of this issue requires user interaction, where a victim must open a malicious file.
Recommendations For Adobe Acrobat Reader versions 22.001.20142 and earlier, update to a version later than 22.001.20142 to resolve the issue. For Adobe Acrobat Reader versions 20.005.30334 and earlier, update to a version later than 20.005.30334 to resolve the issue. For Adobe Acrobat Reader versions 17.012.30229 and earlier, update to a version later than 17.012.30229 to resolve the issue. As a temporary workaround, consider avoiding the use of the printWithParams function until a patch is available. Restrict access to malicious files to minimize the risk of exploitation.

Fix

Use After Free

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2022-04473
CVE-2022-34234
ZDI-22-984

Affected Products

Acrobat Reader