CVE-2022-34221Type Confusion in Adobe Acrobat Reader

CWE-843Type Confusion5 documents4 sources
Severity
7.8HIGHNVD
EPSS
0.2%
top 53.47%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJul 15
Latest updateJul 16

Description

Adobe Acrobat Reader versions 22.001.20142 (and earlier), 20.005.30334 (and earlier) and 17.012.30229 (and earlier) are affected by an Access of Resource Using Incompatible Type ('Type Confusion') vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:HExploitability: 1.8 | Impact: 5.9

Affected Packages5 packages

CVEListV5adobe/acrobat_readerunspecified22.001.20142+3
NVDadobe/acrobat_reader20.001.3000520.005.30334+3
NVDadobe/acrobat_reader_dc15.008.2008222.001.20142
NVDadobe/acrobat20.001.3000520.005.30334+3
NVDadobe/acrobat_dc15.008.2008222.001.20142

🔴Vulnerability Details

2
GHSA
GHSA-qh33-pw65-rh3v: Adobe Acrobat Reader versions 222022-07-16
CVEList
Adobe Acrobat Reader Type Confusion vulnerability could lead to Arbitrary code execution2022-07-15

🕵️Threat Intelligence

2
Talos
Vulnerability Spotlight: Adobe Acrobat DC use-after-free issues could lead to arbitrary code execution2022-07-13
Talos
Vulnerability Spotlight: Adobe Acrobat DC use-after-free issues could lead to arbitrary code execution2022-07-13
CVE-2022-34221 — Type Confusion in Adobe Acrobat Reader | cvebase