PT-2022-7058 · Adobe · Photoshop

Published

2022-04-12

·

Updated

2022-05-13

·

CVE-2022-28271

CVSS v2.0

9.3

High

VectorAV:N/AC:M/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Adobe Photoshop versions 22.5.6 and earlier Adobe Photoshop versions 23.2.2 and earlier
Description The issue is related to a use-after-free vulnerability in the handling of memory. This could allow an attacker to execute arbitrary code in the context of the current user by using a specially crafted PDF file. Exploitation requires user interaction, where the victim must open a malicious PDF file.
Recommendations For Adobe Photoshop versions 22.5.6 and earlier, update to a version later than 22.5.6 to resolve the issue. For Adobe Photoshop versions 23.2.2 and earlier, update to a version later than 23.2.2 to resolve the issue.

Fix

Use After Free

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2023-07297
CVE-2022-28271
ZDI-22-695

Affected Products

Photoshop