CVE-2022-35691NULL Pointer Dereference in Adobe Acrobat

Severity
5.5MEDIUMNVD
EPSS
0.1%
top 69.21%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedOct 14
Latest updateOct 15

Description

Adobe Acrobat Reader versions 22.002.20212 (and earlier) and 20.005.30381 (and earlier) are affected by a NULL Pointer Dereference vulnerability. An unauthenticated attacker could leverage this vulnerability to achieve an application denial-of-service in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

CVSS vector

CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:N/I:N/A:HExploitability: 1.8 | Impact: 3.6

Affected Packages5 packages

NVDadobe/acrobat_reader20.001.3000520.005.30407
NVDadobe/acrobat_reader_dc15.008.2008222.003.20258
CVEListV5adobe/acrobat_readerunspecified20.005.30381+2
NVDadobe/acrobat20.001.3000520.005.30407
NVDadobe/acrobat_dc15.008.2008222.003.20258

Patches

🔴Vulnerability Details

2
GHSA
GHSA-gp5x-9qq8-xxpf: Adobe Acrobat Reader versions 222022-10-15
CVEList
Adobe Acrobat Reader NULL Pointer Dereference Application denial-of-service2022-10-14
CVE-2022-35691 — NULL Pointer Dereference in Adobe | cvebase