CVE-2022-28244: Adobe Acrobat Reader DC CSP Bypass Leads To Privilege Escalation
Acrobat Reader DC versions 22.001.20085 (and earlier), 20.005.3031x (and earlier) and 17.012.30205 (and earlier) is affected by a violation of secure design principles through bypassing the content security policy, which could result in an attacker sending arbitrarily configured requests to the cross-origin attack target domain. Exploitation requires user interaction in which the victim needs to access a crafted PDF file on an attacker's server.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2022-28244?
CVE-2022-28244 has been classified as a critical vulnerability due to its potential impact on content security policy violations.
How do I fix CVE-2022-28244?
To mitigate CVE-2022-28244, upgrade to Adobe Acrobat and Acrobat Reader DC versions later than 22.001.20085, 20.005.30314, and 17.012.30205.
What versions of Adobe Acrobat DC are affected by CVE-2022-28244?
Adobe Acrobat DC versions up to and including 22.001.20085 are vulnerable to CVE-2022-28244.
What versions of Adobe Acrobat Reader are impacted by CVE-2022-28244?
Adobe Acrobat Reader versions up to and including 20.005.30314 and 17.012.30205 are affected by CVE-2022-28244.
Can CVE-2022-28244 be exploited remotely?
Yes, CVE-2022-28244 can be exploited remotely, allowing attackers to bypass security policies.