CVE-2022-28244Violation of Secure Design Principles in Adobe Acrobat Reader

Severity
6.3MEDIUMNVD
EPSS
1.4%
top 19.67%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedMay 11
Latest updateMay 12

Description

Acrobat Reader DC versions 22.001.20085 (and earlier), 20.005.3031x (and earlier) and 17.012.30205 (and earlier) is affected by a violation of secure design principles through bypassing the content security policy, which could result in an attacker sending arbitrarily configured requests to the cross-origin attack target domain. Exploitation requires user interaction in which the victim needs to access a crafted PDF file on an attacker's server.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:C/C:H/I:N/A:NExploitability: 1.8 | Impact: 4.0

Affected Packages5 packages

CVEListV5adobe/acrobat_readerunspecified22.001.20085+3
NVDadobe/acrobat_reader17.011.3005917.012.30205+2
NVDadobe/acrobat_reader_dc15.008.2008222.001.20085
NVDadobe/acrobat17.011.3005917.012.30205+2
NVDadobe/acrobat_dc15.008.2008222.001.20085

🔴Vulnerability Details

2
GHSA
GHSA-j69f-2mqm-rh7p: Acrobat Reader DC versions 222022-05-12
CVEList
Adobe Acrobat Reader DC CSP Bypass Leads To Privilege Escalation2022-05-11

🕵️Threat Intelligence

1
Zscaler
Zscaler found Adobe security vulnerabilities | 04-12-2022
CVE-2022-28244 — Violation of Secure Design Principles | cvebase