CVE-2022-38426: Adobe Photoshop U3D File Parsing Uninitialized Variable Remote Code Execution Vulnerability
Published Sep 16, 2022
·Updated
Adobe Photoshop versions 22.5.8 (and earlier) and 23.4.2 (and earlier) are affected by an Access of Uninitialized Pointer vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Affected Software
4 affected components
Adobe Photoshop>=22.0<=22.5.8
Adobe Photoshop>=23.0<=23.4.2
macOS
Microsoft Windows
Event History
Sep 16, 2022
CVE Published
via MITRE·05:16 PM
Data Sourced
via MITRE·05:16 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the vulnerability ID?
The vulnerability ID is CVE-2022-38426.
2
Which software versions are affected?
Adobe Photoshop versions 22.5.8 (and earlier) and 23.4.2 (and earlier) are affected.
3
What is the severity of CVE-2022-38426?
The severity of CVE-2022-38426 is high with a CVSS score of 7.8.
4
What is the impact of CVE-2022-38426?
The vulnerability could result in arbitrary code execution in the context of the current user.
5
How can the vulnerability be exploited?
Exploitation of CVE-2022-38426 requires user interaction, where a victim must open a malicious file or visit a malicious website.