CVE-2022-34224: Adobe Acrobat Reader DC AcroForm setItems Use-After-Free Remote Code Execution Vulnerability
Published Sep 11, 2023
·Updated
Adobe Acrobat Reader versions 22.001.20142 (and earlier), 20.005.30334 (and earlier) and 17.012.30229 (and earlier) are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Affected Software
12 affected components
Adobe Acrobat DC>=15.008.20082<=22.001.20142
Adobe Acrobat Reader DC>=15.008.20082<=22.001.20142
Apple macOS
Microsoft Windows
Adobe Acrobat>=20.001.30005<=20.005.30334
Adobe Acrobat Reader>=20.001.30005<=20.005.30334
Adobe Acrobat>=20.001.30005<=20.005.30331
Adobe Acrobat Reader>=20.001.30005<=20.005.30331
Adobe Acrobat>=17.011.30059<=17.012.30229
Adobe Acrobat Reader>=17.011.30059<=17.012.30229
Adobe Acrobat>=17.011.30059<=17.012.30227
Adobe Acrobat Reader>=17.011.30059<=17.012.30227
Event History
Sep 11, 2023
CVE Published
via MITRE·01:22 PM
Data Sourced
via MITRE·01:22 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the vulnerability ID?
The vulnerability ID is CVE-2022-34224.
2
What is the severity of CVE-2022-34224?
The severity of CVE-2022-34224 is high with a CVSS score of 7.8.
3
Which versions of Adobe Acrobat Reader are affected?
Adobe Acrobat Reader versions 22.001.20142 (and earlier), 20.005.30334 (and earlier) and 17.012.30229 (and earlier) are affected.
4
What is the impact of this vulnerability?
This vulnerability could result in arbitrary code execution in the context of the current user.
5
How can this vulnerability be exploited?
Exploitation of this issue requires user interaction.