CVE-2022-34238: Adobe Acrobat Reader DC Font Parsing Out-Of-Bounds Read Information Disclosure Vulnerability
Acrobat Reader versions 22.001.20142 (and earlier), 20.005.30334 (and earlier) and 20.005.30334 (and earlier) are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2022-34238?
CVE-2022-34238 is an out-of-bounds read vulnerability in Acrobat Reader versions 22.001.20142 and earlier.
How does CVE-2022-34238 affect Adobe Acrobat DC?
Adobe Acrobat DC versions between 15.008.20082 and 22.001.20142 are affected by CVE-2022-34238.
How does CVE-2022-34238 affect Adobe Acrobat Reader DC?
Adobe Acrobat Reader DC versions between 15.008.20082 and 22.001.20142 are affected by CVE-2022-34238.
What is the severity of CVE-2022-34238?
CVE-2022-34238 has a severity value of 5.5 (medium).
How can I fix CVE-2022-34238?
To fix CVE-2022-34238, update your Acrobat Reader to version 22.001.20142 or later.