CVE-2022-28242: Adobe Acrobat Reader DC Annotation Use-After-Free Remote Code Execution Vulnerability
Acrobat Reader DC version 22.001.2011x (and earlier), 20.005.3033x (and earlier) and 17.012.3022x (and earlier) are affected by a use-after-free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2022-28242?
CVE-2022-28242 is a critical vulnerability that allows for arbitrary code execution due to a use-after-free condition.
How do I fix CVE-2022-28242?
To fix CVE-2022-28242, update Adobe Acrobat Reader DC to version 22.001.2011 or later, or the appropriate fixed version for earlier releases.
Which versions of Adobe Acrobat Reader are affected by CVE-2022-28242?
Adobe Acrobat Reader DC versions up to 22.001.20085, 20.005.3033, and 17.012.3022 are affected by CVE-2022-28242.
What could be the impact of exploiting CVE-2022-28242?
Exploitation of CVE-2022-28242 could allow an attacker to execute arbitrary code in the context of the current user.
Is it possible to exploit CVE-2022-28242 without user interaction?
Exploitation of CVE-2022-28242 requires user interaction, as the vulnerability relies on the user opening a malicious document.