CVE-2022-38428: Adobe Photoshop DCM File Parsing Use-After-Free Information Disclosure Vulnerability
Published Sep 16, 2022
·Updated
Adobe Photoshop versions 22.5.8 (and earlier) and 23.4.2 (and earlier) are affected by a Use After Free vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Affected Software
4 affected components
Adobe Photoshop>=22.0<=22.5.8
Adobe Photoshop>=23.0<=23.4.2
macOS
Microsoft Windows
Event History
Sep 16, 2022
CVE Published
via MITRE·05:16 PM
Data Sourced
via MITRE·05:16 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the vulnerability ID?
The vulnerability ID is CVE-2022-38428.
2
What is the severity of CVE-2022-38428?
The severity of CVE-2022-38428 is medium.
3
Which versions of Adobe Photoshop are affected by CVE-2022-38428?
Adobe Photoshop versions 22.5.8 (and earlier) and 23.4.2 (and earlier) are affected.
4
What is the impact of CVE-2022-38428?
The vulnerability could lead to disclosure of sensitive memory and bypassing mitigations such as ASLR.
5
Is Apple macOS or Microsoft Windows affected by CVE-2022-38428?
No, Apple macOS and Microsoft Windows are not affected.