First published: Mon Sep 19 2022(Updated: )
Adobe Bridge version 12.0.2 (and earlier) and 11.1.3 (and earlier) are affected by a Use After Free vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Credit: psirt@adobe.com
Affected Software | Affected Version | How to fix |
---|---|---|
Adobe Bridge | >=11.1<11.1.4 | |
Adobe Bridge | >=12.0<12.0.3 | |
Apple macOS | ||
Microsoft Windows |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-35709 is a Use After Free vulnerability in Adobe Bridge, versions 12.0.2 and earlier, and 11.1.3 and earlier, which could lead to disclosure of sensitive memory.
CVE-2022-35709 affects Adobe Bridge by allowing an attacker to exploit a Use After Free vulnerability and potentially disclose sensitive memory.
CVE-2022-35709 has a severity rating of 5.5, which is considered medium.
Versions 12.0.2 and earlier, as well as 11.1.3 and earlier, of Adobe Bridge are affected by CVE-2022-35709.
An attacker can exploit CVE-2022-35709 by leveraging the Use After Free vulnerability in Adobe Bridge, potentially bypassing mitigations such as ASLR.