First published: Tue Apr 12 2022(Updated: )
Acrobat Reader DC version 22.001.2011x (and earlier), 20.005.3033x (and earlier) and 17.012.3022x (and earlier) are affected by an out-of-bounds read vulnerability when parsing a crafted file, which could result in a read past the end of an allocated memory structure. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Credit: psirt@adobe.com
Affected Software | Affected Version | How to fix |
---|---|---|
Adobe Acrobat | >=15.008.20082<=22.001.20085 | |
Adobe Acrobat Reader | >=15.008.20082<=22.001.20085 | |
Apple iOS and macOS | ||
Microsoft Windows | ||
Adobe Acrobat Reader | >=17.011.30059<=17.012.30205 | |
Adobe Acrobat Reader | >=17.011.30059<=17.012.30205 | |
Adobe Acrobat Reader | >=20.001.30005<=20.005.30314 | |
Adobe Acrobat Reader | >=20.001.30005<=20.005.30314 | |
Adobe Acrobat Reader | >=20.001.30005<=20.005.30311 | |
Adobe Acrobat Reader | >=20.001.30005<=20.005.30311 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-28263 has been assigned a severity rating of important due to its potential for exploitation through crafted files.
CVE-2022-28263 is an out-of-bounds read vulnerability in Adobe Acrobat Reader DC that could allow an attacker to read past allocated memory.
To fix CVE-2022-28263, users should update Adobe Acrobat Reader DC to the latest version provided by Adobe.
Adobe Acrobat Reader DC version 22.001.2011 and earlier, 20.005.3033 and earlier, as well as 17.012.3022 and earlier are affected by CVE-2022-28263.
No, CVE-2022-28263 specifically affects the Adobe Acrobat Reader DC software and does not affect macOS or Windows directly.