CVE-2022-28234: Adobe Acrobat Reader DC Heap Overflow Could Lead to RCE
Acrobat Reader DC versions 22.001.20085 (and earlier), 20.005.3031x (and earlier) and 17.012.30205 (and earlier) is affected by a heap-based buffer overflow vulnerability due to insecure handling of a crafted .pdf file, potentially resulting in arbitrary code execution in the context of the current user. Exploitation requires user interaction in that a victim must open a crafted .pdf file
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2022-28234?
CVE-2022-28234 is considered critical due to the potential for arbitrary code execution.
How do I fix CVE-2022-28234?
To fix CVE-2022-28234, update Adobe Acrobat DC or Acrobat Reader DC to the latest version as specified in the vendor's security advisory.
Which versions are affected by CVE-2022-28234?
CVE-2022-28234 affects Adobe Acrobat Reader DC versions up to 22.001.20085 and Adobe Acrobat versions up to 17.012.30205.
What types of attacks can exploit CVE-2022-28234?
CVE-2022-28234 can be exploited through crafted PDF files that lead to a heap-based buffer overflow.
Is CVE-2022-28234 relevant for Mac or Windows users?
Yes, CVE-2022-28234 is relevant for users of Adobe Acrobat products on both Mac and Windows.