CVE-2022-24090: Adobe Photoshop 2022 Out-of-bounds Read could lead to Memory leak
Published Mar 11, 2022
·Updated
Adobe Photoshop versions 23.1.1 (and earlier) and 22.5.5 (and earlier) are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Affected Software
4 affected components
Adobe Photoshop>=21.0<=21.3.3
Adobe Photoshop>=22.0<=22.5.5
macOS
Microsoft Windows
Remediation
Event History
Mar 11, 2022
CVE Published
via MITRE·05:54 PM
Data Sourced
via MITRE·05:54 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the vulnerability ID?
The vulnerability ID is CVE-2022-24090.
2
Which versions of Adobe Photoshop are affected?
Adobe Photoshop versions 23.1.1 and earlier, and 22.5.5 and earlier, are affected.
3
What is the severity of CVE-2022-24090?
The severity of CVE-2022-24090 is medium, with a severity value of 5.5.
4
How can the vulnerability be exploited?
The vulnerability can be exploited to perform an out-of-bounds read, leading to disclosure of sensitive memory.
5
Are Apple macOS and Microsoft Windows vulnerable to this vulnerability?
No, Apple macOS and Microsoft Windows are not vulnerable to CVE-2022-24090.