CVE-2022-28273
published 2022-05-06CVE-2022-28273: Adobe Photoshop versions 22.5.6 (and earlier) and 23.2.2 (and earlier) are affected by an out-of-bounds write vulnerability that could result in arbitrary code…
PriorityP344high7.8CVSS 3.0
AVLACLPRNUIRSUCHIHAH
EPSS
2.24%
80.9th percentile
Adobe Photoshop versions 22.5.6 (and earlier) and 23.2.2 (and earlier) are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Affected
4 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| adobe | photoshop | <= 22.5.6 | — |
| adobe | photoshop | 23.0.0 – 23.2.2 | — |
| adobe | photoshop | unspecified – 22.5.6 | — |
| set-in_project | set-in | >= 0 < 2.0.3 | 2.0.3 |
CVSS provenance
nvdv3.07.8HIGHCVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.09.3CRITICALAV:N/AC:M/Au:N/C:C/I:C/A:C
ghsa9.8CRITICAL
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-rpp6-r6fh-2cw7: Adobe Photoshop versions 22
ghsa_unreviewed·2022-05-07
CVE-2022-28273 [HIGH] CWE-787 GHSA-rpp6-r6fh-2cw7: Adobe Photoshop versions 22
Adobe Photoshop versions 22.5.6 (and earlier) and 23.2.2 (and earlier) are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
GHSA
Prototype Pollution in set-in
ghsa·2022-03-18·CVSS 9.8
CVE-2022-25354 [CRITICAL] CWE-1321 Prototype Pollution in set-in
Prototype Pollution in set-in
The package set-in before 2.0.3 is vulnerable to Prototype Pollution via the `setIn` method, as it allows an attacker to merge object prototypes into it. **Note:** This vulnerability derives from an incomplete fix of [CVE-2020-28273](https://security.snyk.io/vuln/SNYK-JS-SETIN-1048049)
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2022-05-06
Published