CVE-2022-35670: Adobe Acrobat Reader Use-After-Free Memory leak
Adobe Acrobat Reader versions 22.001.20169 (and earlier), 20.005.30362 (and earlier) and 17.012.30249 (and earlier) are affected by a Use After Free vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2022-35670?
CVE-2022-35670 is classified as a critical vulnerability due to its potential to allow sensitive memory disclosure.
How do I fix CVE-2022-35670?
To fix CVE-2022-35670, you should update Adobe Acrobat Reader to the latest version available.
What versions of Adobe Acrobat are affected by CVE-2022-35670?
Versions 22.001.20169 and earlier, 20.005.30362 and earlier, and 17.012.30249 and earlier of Adobe Acrobat are affected by CVE-2022-35670.
Can CVE-2022-35670 be exploited remotely?
Yes, CVE-2022-35670 can potentially be exploited by an attacker to remotely execute code through crafted PDF files.
What type of vulnerability is CVE-2022-35670?
CVE-2022-35670 is categorized as a Use After Free vulnerability.