CVE-2022-28265: Adobe Acrobat Reader DC Annotation Out-Of-Bounds Read Information Disclosure Vulnerability
Acrobat Reader DC version 22.001.2011x (and earlier), 20.005.3033x (and earlier) and 17.012.3022x (and earlier) are affected by an out-of-bounds read vulnerability when parsing a crafted file, which could result in a read past the end of an allocated memory structure. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2022-28265?
The severity of CVE-2022-28265 is classified as critical due to the potential for an attacker to exploit the out-of-bounds read vulnerability.
How do I fix CVE-2022-28265?
To fix CVE-2022-28265, update Adobe Acrobat Reader to the latest version that addresses the vulnerability.
Which versions are affected by CVE-2022-28265?
CVE-2022-28265 affects Adobe Acrobat Reader DC version 22.001.2011x and earlier, 20.005.3033x and earlier, and 17.012.3022x and earlier.
What types of attacks can occur due to CVE-2022-28265?
CVE-2022-28265 can lead to information disclosure or potentially be leveraged for further exploitation through crafted files.
Can I still use Adobe Acrobat Reader if I have CVE-2022-28265?
Using an affected version of Adobe Acrobat Reader poses risks; it is recommended to update to mitigate vulnerabilities like CVE-2022-28265.