CVE-2022-38449: Adobe Acrobat Reader DC JP2 File Parsing Out-Of-Bounds Read Information Disclosure Vulnerability
Adobe Acrobat Reader versions 22.002.20212 (and earlier) and 20.005.30381 (and earlier) are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2022-38449?
CVE-2022-38449 has been classified as a high-severity vulnerability due to the potential for sensitive memory disclosure.
How do I fix CVE-2022-38449?
To fix CVE-2022-38449, update Adobe Acrobat or Adobe Acrobat Reader to the latest version provided by Adobe.
What versions are affected by CVE-2022-38449?
CVE-2022-38449 affects Adobe Acrobat Reader versions 22.002.20212 and earlier, and Adobe Acrobat versions 20.005.30381 and earlier.
What are the potential impacts of CVE-2022-38449?
Exploitation of CVE-2022-38449 could lead to the disclosure of sensitive memory and enable attackers to bypass security mitigations like ASLR.
Is CVE-2022-38449 specific to any operating systems?
CVE-2022-38449 is found in specific versions of Adobe software and is not limited to particular operating systems.