CVE-2022-42342: Adobe Acrobat Reader DC Font Parsing Out-Of-Bounds Read Information Disclosure Vulnerability
Adobe Acrobat Reader versions 22.002.20212 (and earlier) and 20.005.30381 (and earlier) are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Adobe Acrobat Reader DCto a version that resolves this vulnerability.Fixed in 22.002.20212 - Upgrade
Upgrade
Adobe Acrobat Reader DCto a version that resolves this vulnerability.Fixed in 20.005.30381
Event History
Frequently Asked Questions
What is the severity of CVE-2022-42342?
CVE-2022-42342 is considered a high-severity vulnerability due to its potential to disclose sensitive memory and bypass security mitigations.
How do I fix CVE-2022-42342?
To mitigate CVE-2022-42342, update Adobe Acrobat Reader to version 22.003.20258 or later, or version 20.005.30407 or later.
What versions of Adobe Acrobat are affected by CVE-2022-42342?
CVE-2022-42342 affects Adobe Acrobat Reader versions 22.002.20212 and earlier, and 20.005.30381 and earlier.
Can CVE-2022-42342 be exploited remotely?
Yes, CVE-2022-42342 can be exploited remotely by an attacker to disclose sensitive information.
What platforms are impacted by CVE-2022-42342?
CVE-2022-42342 impacts Adobe Acrobat and Adobe Acrobat Reader on supported versions for various operating systems.