CVE-2022-28232: Adobe Acrobat Reader DC Collab Object Use-After-Free Information Disclosure Vulnerability
Acrobat Reader DC versions 22.001.20085 (and earlier), 20.005.3031x (and earlier) and 17.012.30205 (and earlier) are affected by a use-after-free vulnerability in the processing of the collab object that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2022-28232?
CVE-2022-28232 has been rated as critical due to its potential to allow arbitrary code execution.
How do I fix CVE-2022-28232?
To mitigate CVE-2022-28232, users should update to the latest version of Adobe Acrobat Reader DC that addresses this vulnerability.
What versions are affected by CVE-2022-28232?
CVE-2022-28232 affects Adobe Acrobat Reader DC versions 22.001.20085 and earlier, along with specific versions in the 20.x and 17.x series.
Can exploitation of CVE-2022-28232 lead to data loss?
Yes, exploitation of CVE-2022-28232 could potentially lead to data loss if arbitrary code execution is achieved.
Is CVE-2022-28232 a local or remote vulnerability?
CVE-2022-28232 is primarily considered a local vulnerability as it requires the attacker to have access to the affected system.