CVE-2022-35706: Adobe Bridge SVG File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability
Adobe Bridge version 12.0.2 (and earlier) and 11.1.3 (and earlier) are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2022-35706?
The severity of CVE-2022-35706 is high with a CVSS score of 7.8.
Which versions of Adobe Bridge are affected by CVE-2022-35706?
Adobe Bridge version 12.0.2 (and earlier) and 11.1.3 (and earlier) are affected.
What is the vulnerability type of CVE-2022-35706?
CVE-2022-35706 is a Heap-based Buffer Overflow vulnerability.
What is the potential impact of CVE-2022-35706?
Exploitation of CVE-2022-35706 could result in arbitrary code execution in the context of the current user.
How can CVE-2022-35706 be exploited?
Exploitation of CVE-2022-35706 requires user interaction in that a victim must open a malicious file.
Is Apple macOS or Microsoft Windows affected by CVE-2022-35706?
No, Apple macOS and Microsoft Windows are not vulnerable to CVE-2022-35706.
Where can I find more information about CVE-2022-35706?
You can find more information about CVE-2022-35706 at the following link: [Adobe Security Bulletin APSB22-49](https://helpx.adobe.com/security/products/bridge/apsb22-49.html).
What are the Common Weakness Enumerations (CWE) associated with CVE-2022-35706?
CVE-2022-35706 is associated with the following CWEs: CWE-119 (Improper Restriction of Operations within the Bounds of a Memory Buffer) and CWE-122 (Heap-based Buffer Overflow).