First published: Fri Oct 14 2022(Updated: )
Adobe Acrobat Reader versions 22.002.20212 (and earlier) and 20.005.30381 (and earlier) are affected by a Stack-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Credit: psirt@adobe.com
Affected Software | Affected Version | How to fix |
---|---|---|
Adobe Acrobat Reader | >=15.008.20082<22.003.20258 | |
Adobe Acrobat Reader Notification Manager | >=15.008.20082<22.003.20258 | |
Apple iOS and macOS | ||
Microsoft Windows | ||
Adobe Acrobat Reader | >=20.001.30005<20.005.30407 | |
Adobe Acrobat Reader Notification Manager | >=20.001.30005<20.005.30407 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-42339 is a Stack-based Buffer Overflow vulnerability found in Adobe Acrobat Reader versions 22.002.20212 (and earlier) and 20.005.30381 (and earlier).
CVE-2022-42339 has a severity score of 7.8 out of 10, making it a high severity vulnerability.
CVE-2022-42339 could result in arbitrary code execution in the context of the current user if exploited.
Adobe Acrobat Reader versions 22.002.20212 (and earlier) and 20.005.30381 (and earlier) are affected by CVE-2022-42339.
To fix CVE-2022-42339, users should update to a version of Adobe Acrobat Reader that is not affected by the vulnerability.