CVE-2022-28237: Adobe Acrobat Reader DC Annotation Use-After-Free Remote Code Execution Vulnerability
Acrobat Reader DC versions 22.001.20085 (and earlier), 20.005.3031x (and earlier) and 17.012.30205 (and earlier) are affected by a use-after-free vulnerability in the processing of annotations that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2022-28237?
CVE-2022-28237 has a severity rating that allows for arbitrary code execution in the context of the current user.
How do I fix CVE-2022-28237?
To fix CVE-2022-28237, update to the latest version of Adobe Acrobat Reader DC as per the recommended security update.
Which versions of Adobe Acrobat Reader are affected by CVE-2022-28237?
CVE-2022-28237 affects Adobe Acrobat Reader DC versions 22.001.20085 and earlier, 20.005.3031x and earlier, and 17.012.30205 and earlier.
What is a use-after-free vulnerability as seen in CVE-2022-28237?
A use-after-free vulnerability like CVE-2022-28237 occurs when a program continues to use memory after it has been freed, potentially allowing attackers to execute arbitrary code.
Is it safe to use versions of Acrobat Reader older than 22.001.20085 with CVE-2022-28237?
No, using versions of Acrobat Reader older than 22.001.20085 poses a significant security risk due to CVE-2022-28237.