CVE-2022-34243: Adobe Photoshop U3D File Parsing Use-After-Free Remote Code Execution Vulnerability
Published Jul 15, 2022
·Updated
Adobe Photoshop versions 22.5.7 (and earlier) and 23.3.2 (and earlier) are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Affected Software
4 affected components
Adobe Photoshop<=22.5.7
Adobe Photoshop>=23.0.0<=23.3.2
macOS
Microsoft Windows
Event History
Jul 15, 2022
CVE Published
via MITRE·03:41 PM
Data Sourced
via MITRE·03:41 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is CVE-2022-34243?
CVE-2022-34243 is a Use After Free vulnerability in Adobe Photoshop versions 22.5.7 and earlier, and 23.3.2 and earlier.
2
How does CVE-2022-34243 affect Adobe Photoshop?
CVE-2022-34243 can result in arbitrary code execution in the context of the current user in Adobe Photoshop.
3
What is the severity of CVE-2022-34243?
The severity of CVE-2022-34243 is high, with a CVSS score of 7.8.
4
How do I fix CVE-2022-34243?
To fix CVE-2022-34243, it is recommended to update Adobe Photoshop to versions 22.5.8 or 23.4 or later.
5
Is Microsoft Windows affected by CVE-2022-34243?
No, Microsoft Windows is not affected by CVE-2022-34243.