PT-2022-6423 · Adobe · Acrobat+1

Published

2022-10-11

·

Updated

2022-10-19

·

CVE-2022-35691

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:H
Name of the Vulnerable Software and Affected Versions Adobe Acrobat Reader versions 22.002.20212 and earlier Adobe Acrobat Reader versions 20.005.30381 and earlier Adobe Acrobat 2020 Adobe Acrobat Reader 2020
Description The issue is related to a NULL Pointer Dereference, which could allow an unauthenticated attacker to cause an application denial-of-service in the context of the current user. Exploitation requires user interaction, such as opening a malicious file, and can lead to a denial-of-service.
Recommendations For Adobe Acrobat Reader versions 22.002.20212 and earlier, update to a version later than 22.002.20212 to resolve the issue. For Adobe Acrobat Reader versions 20.005.30381 and earlier, update to a version later than 20.005.30381 to resolve the issue. For Adobe Acrobat 2020 and Adobe Acrobat Reader 2020, consider disabling the handling of malicious PDF files until a patch is available. As a temporary workaround, avoid opening suspicious or untrusted PDF files with the affected Adobe Acrobat and Reader versions until the issue is resolved.

Fix

DoS

NULL Pointer Dereference

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2023-01226
CVE-2022-35691

Affected Products

Acrobat
Acrobat Reader