CVE-2022-34237: Adobe Acrobat Reader DC Font Parsing Use-After-Free Information Disclosure Vulnerability
Adobe Acrobat Reader versions 22.001.20142 (and earlier), 20.005.30334 (and earlier) and 17.012.30229 (and earlier) are affected by a Use After Free vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file..
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID?
The vulnerability ID is CVE-2022-34237.
Which software versions are affected by CVE-2022-34237?
Adobe Acrobat Reader versions 22.001.20142 (and earlier), 20.005.30334 (and earlier), and 17.012.30229 (and earlier) are affected.
What is the severity of CVE-2022-34237?
CVE-2022-34237 has a severity rating of 5.5 (Medium).
What is the impact of CVE-2022-34237?
The vulnerability in Adobe Acrobat Reader could lead to the disclosure of sensitive memory and bypassing of mitigations such as ASLR.
Is there a fix available for CVE-2022-34237?
Yes, Adobe has released a security update to address the vulnerability. It is recommended to update to the latest version of Adobe Acrobat Reader.