CVE-2022-28270: Adobe Photoshop SVG File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability
Adobe Photoshop versions 22.5.6 (and earlier) and 23.2.2 (and earlier) are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious SVG file.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2022-28270?
The severity of CVE-2022-28270 is critical.
Which versions of Adobe Photoshop are affected by CVE-2022-28270?
Adobe Photoshop versions 22.5.6 and earlier, as well as 23.2.2 and earlier, are affected by CVE-2022-28270.
What is the impact of CVE-2022-28270?
CVE-2022-28270 could result in arbitrary code execution in the context of the current user.
Is user interaction required to exploit CVE-2022-28270?
Yes, user interaction is required to exploit CVE-2022-28270. The victim must open a malicious SV file.
Is there a fix available for CVE-2022-28270?
Yes, Adobe has released a security update to address CVE-2022-28270. Please refer to the reference link for more information.