First published: Tue Jul 12 2022(Updated: )
Adobe Acrobat Reader versions 22.001.20142 (and earlier), 20.005.30334 (and earlier) and 17.012.30229 (and earlier) are affected by an Access of Resource Using Incompatible Type ('Type Confusion') vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Credit: psirt@adobe.com
Affected Software | Affected Version | How to fix |
---|---|---|
Adobe Acrobat | >=15.008.20082<=22.001.20142 | |
Adobe Acrobat Reader | >=15.008.20082<=22.001.20142 | |
Apple iOS and macOS | ||
Microsoft Windows | ||
Adobe Acrobat Reader | >=20.001.30005<=20.005.30334 | |
Adobe Acrobat Reader | >=20.001.30005<=20.005.30334 | |
Adobe Acrobat Reader | >=20.001.30005<=20.005.30331 | |
Adobe Acrobat Reader | >=20.001.30005<=20.005.30331 | |
Adobe Acrobat Reader | >=17.011.30059<=17.012.30229 | |
Adobe Acrobat Reader | >=17.011.30059<=17.012.30229 | |
Adobe Acrobat Reader | >=17.011.30059<=17.012.30227 | |
Adobe Acrobat Reader | >=17.011.30059<=17.012.30227 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-34221 is considered a critical vulnerability that can lead to arbitrary code execution.
To fix CVE-2022-34221, upgrade to the latest version of Adobe Acrobat Reader or Adobe Acrobat.
CVE-2022-34221 affects Adobe Acrobat Reader versions 22.001.20142 and earlier, 20.005.30334 and earlier, as well as 17.012.30229 and earlier.
Exploitation of CVE-2022-34221 can allow attackers to execute arbitrary code in the context of the user.
No, only specific versions of Adobe Acrobat Reader and Adobe Acrobat are vulnerable to CVE-2022-34221.