CVE-2022-28246: Adobe Acrobat Reader DC Doc Object Out-Of-Bounds Read Information Disclosure Vulnerability
Published May 11, 2022
·Updated
Acrobat Reader DC version 22.001.2011x (and earlier), 20.005.3033x (and earlier) and 17.012.3022x (and earlier) are affected by an out-of-bounds read vulnerability when parsing a crafted file, which could result in a read past the end of an allocated memory structure. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Affected Software
10 affected components
Adobe Acrobat DC>=15.008.20082<=22.001.20085
Adobe Acrobat Reader DC>=15.008.20082<=22.001.20085
Apple macOS
Microsoft Windows
Adobe Acrobat>=17.011.30059<=17.012.30205
Adobe Acrobat Reader>=17.011.30059<=17.012.30205
Adobe Acrobat>=20.001.30005<=20.005.30314
Adobe Acrobat Reader>=20.001.30005<=20.005.30314
Adobe Acrobat>=20.001.30005<=20.005.30311
Adobe Acrobat Reader>=20.001.30005<=20.005.30311
Event History
May 11, 2022
CVE Published
via MITRE·05:41 PM
Data Sourced
via MITRE·05:41 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Is there a workaround for CVE-2022-28246 if I cannot update immediately?
Currently, there are no known workarounds for CVE-2022-28246 other than promptly applying the security updates from Adobe.