cbcvebase.
CVE-2022-28244
published 2022-05-11

CVE-2022-28244: Acrobat Reader DC versions 22.001.20085 (and earlier), 20.005.3031x (and earlier) and 17.012.30205 (and earlier) is affected by a violation of secure design…

PriorityP431medium6.3CVSS 3.1
AVLACLPRNUIRSCCHINAN
EPSS
3.61%
88.3th percentile
Acrobat Reader DC versions 22.001.20085 (and earlier), 20.005.3031x (and earlier) and 17.012.30205 (and earlier) is affected by a violation of secure design principles through bypassing the content security policy, which could result in an attacker sending arbitrarily configured requests to the cross-origin attack target domain. Exploitation requires user interaction in which the victim needs to access a crafted PDF file on an attacker's server.

Affected

9 ranges
VendorProductVersion rangeFixed in
adobeacrobat17.011.30059 – 17.012.30205
adobeacrobat20.001.30005 – 20.005.30314
adobeacrobat20.001.30005 – 20.005.30311
adobeacrobat_dc15.008.20082 – 22.001.20085
adobeacrobat_reader17.011.30059 – 17.012.30205
adobeacrobat_reader20.001.30005 – 20.005.30314
adobeacrobat_reader20.001.30005 – 20.005.30311
adobeacrobat_readerunspecified – 22.001.20085
adobeacrobat_reader_dc15.008.20082 – 22.001.20085

CVSS provenance

nvdv3.16.3MEDIUMCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:N/A:N
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:P/I:N/A:N
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.