First published: Wed May 11 2022(Updated: )
Acrobat Reader DC versions 22.001.20085 (and earlier), 20.005.3031x (and earlier) and 17.012.30205 (and earlier) are affected by a use-after-free vulnerability in the processing of the acroform event that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Credit: psirt@adobe.com
Affected Software | Affected Version | How to fix |
---|---|---|
Adobe Acrobat DC | >=15.008.20082<=22.001.20085 | |
Adobe Acrobat DC | >=15.008.20082<=22.001.20085 | |
Apple macOS | ||
Microsoft Windows | ||
Adobe Acrobat Reader | >=17.011.30059<=17.012.30205 | |
Adobe Acrobat Reader | >=17.011.30059<=17.012.30205 | |
Adobe Acrobat Reader | >=20.001.30005<=20.005.30314 | |
Adobe Acrobat Reader | >=20.001.30005<=20.005.30314 | |
Adobe Acrobat Reader | >=20.001.30005<=20.005.30311 | |
Adobe Acrobat Reader | >=20.001.30005<=20.005.30311 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-27799 has a high severity rating due to its potential to allow arbitrary code execution.
To fix CVE-2022-27799, update Adobe Acrobat Reader DC and Acrobat to the latest version available.
CVE-2022-27799 affects Adobe Acrobat Reader DC versions up to 22.001.20085, Acrobat versions up to 20.005.3031x, and Acrobat versions up to 17.012.30205.
CVE-2022-27799 impacts systems running affected versions of Adobe Acrobat on both Windows and macOS platforms.
Yes, if exploited, CVE-2022-27799 can lead to unauthorized access and potential data breaches.