First published: Tue Apr 12 2022(Updated: )
Acrobat Reader DC version 22.001.2011x (and earlier), 20.005.3033x (and earlier) and 17.012.3022x (and earlier) are affected by a use-after-free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Credit: psirt@adobe.com
Affected Software | Affected Version | How to fix |
---|---|---|
Adobe Acrobat Reader DC | >=15.008.20082<=22.001.20085 | |
Adobe Acrobat Reader | >=15.008.20082<=22.001.20085 | |
macOS | ||
Microsoft Windows Operating System | ||
Adobe Acrobat Reader | >=17.011.30059<=17.012.30205 | |
Adobe Acrobat Reader Notification Manager | >=17.011.30059<=17.012.30205 | |
Adobe Acrobat Reader | >=20.001.30005<=20.005.30314 | |
Adobe Acrobat Reader Notification Manager | >=20.001.30005<=20.005.30314 | |
Adobe Acrobat Reader | >=20.001.30005<=20.005.30311 | |
Adobe Acrobat Reader Notification Manager | >=20.001.30005<=20.005.30311 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-28242 is a critical vulnerability that allows for arbitrary code execution due to a use-after-free condition.
To fix CVE-2022-28242, update Adobe Acrobat Reader DC to version 22.001.2011 or later, or the appropriate fixed version for earlier releases.
Adobe Acrobat Reader DC versions up to 22.001.20085, 20.005.3033, and 17.012.3022 are affected by CVE-2022-28242.
Exploitation of CVE-2022-28242 could allow an attacker to execute arbitrary code in the context of the current user.
Exploitation of CVE-2022-28242 requires user interaction, as the vulnerability relies on the user opening a malicious document.