PT-2022-7068 · Adobe · Acrobat Reader

Published

2022-04-12

·

Updated

2025-01-10

·

CVE-2022-44516

CVSS v3.1

5.5

Medium

VectorAV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Acrobat Reader DC versions 17.012.30205 through 22.001.20085 Acrobat Reader DC versions 20.005.3031x and earlier
Description The issue is related to an out-of-bounds read vulnerability when parsing a crafted file, which could result in a read past the end of an allocated memory structure. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction, in that a victim must open a malicious file.
Recommendations For Acrobat Reader DC versions 17.012.30205 through 22.001.20085, update to a version later than 22.001.20085 to resolve the issue. For Acrobat Reader DC versions 20.005.3031x and earlier, update to a version later than 20.005.3031x to resolve the issue. As a temporary workaround, consider avoiding the use of lineWidth annotation to minimize the risk of exploitation until a patch is available. Restrict access to crafted PDF files to minimize the risk of exploitation.

Fix

Out of bounds Read

Weakness Enumeration

Related Identifiers

BDU:2023-07406
CVE-2022-44516
ZDI-23-732

Affected Products

Acrobat Reader