CVE-2022-44515
published 2024-12-19CVE-2022-44515: Acrobat Reader DC version 22.001.20085 (and earlier), 20.005.3031x (and earlier) and 17.012.30205 (and earlier) are affected by an out-of-bounds read…
PriorityP426medium5.5CVSS 3.1
AVLACLPRNUIRSUCHINAN
EPSS
0.26%
17.8th percentile
Acrobat Reader DC version 22.001.20085 (and earlier), 20.005.3031x (and earlier) and 17.012.30205 (and earlier) are affected by an out-of-bounds read vulnerability when parsing a crafted file, which could result in a read past the end of an allocated memory structure. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Affected
13 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| adobe | acrobat | >= 17.011.30059 < 17.012.30229 | 17.012.30229 |
| adobe | acrobat | >= 17.011.30059 < 17.012.30227 | 17.012.30227 |
| adobe | acrobat | >= 20.001.30002 < 20.005.30334 | 20.005.30334 |
| adobe | acrobat | >= 20.001.30002 < 20.005.30331 | 20.005.30331 |
| adobe | acrobat_dc | >= 22.001.20085 < 22.001.20117 | 22.001.20117 |
| adobe | acrobat_dc | >= 22.001.20085 < 22.001.20112 | 22.001.20112 |
| adobe | acrobat_reader | <= 17.012.30205 | — |
| adobe | acrobat_reader | >= 17.011.30059 < 17.012.30229 | 17.012.30229 |
| adobe | acrobat_reader | >= 17.011.30059 < 17.012.30227 | 17.012.30227 |
| adobe | acrobat_reader | >= 20.001.30002 < 20.005.30334 | 20.005.30334 |
| adobe | acrobat_reader | >= 20.001.30002 < 20.005.30331 | 20.005.30331 |
| adobe | acrobat_reader_dc | >= 22.001.20085 < 22.001.20117 | 22.001.20117 |
| adobe | acrobat_reader_dc | >= 22.001.20085 < 22.001.20112 | 22.001.20112 |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
Suricata
ET EXPLOIT Zoho ManagedEngine Desktop Central Authentication Bypass - Administrator Password Reset Attempt (CVE-2021-44515)
suricata·2022-01-24·CVSS 9.8
CVE-2021-44515 [CRITICAL] ET EXPLOIT Zoho ManagedEngine Desktop Central Authentication Bypass - Administrator Password Reset Attempt (CVE-2021-44515)
ET EXPLOIT Zoho ManagedEngine Desktop Central Authentication Bypass - Administrator Password Reset Attempt (CVE-2021-44515)
Rule: alert http $EXTERNAL_NET any -> $HOME_NET any (msg:"ET EXPLOIT Zoho ManagedEngine Desktop Central Authentication Bypass - Administrator Password Reset Attempt (CVE-2021-44515)"; flow:established,to_server; http.method; content:"POST"; http.uri; content:"/STATE_ID/"; startswith; content:"/changeDefaultAmazonPassword?"; fast_pattern; content:"loginName="; distance:0; content:"newUserPassword="; http.cookie; content:"STATE_COOKIE="; reference:url,srcincite.io/blog/2022/01/20/zohowned-a-critical-authentication-bypass-on-zoho-manageengine-desktop-central.html; reference:cve,2021-44515; classtype:attempted-admin; sid:2034958; rev:2; metadata:created_at 2022_01_24, cv
Suricata
ET EXPLOIT Zoho ManagedEngine Desktop Central Authentication Bypass - File Upload Attempt (CVE-2021-44515)
suricata·2022-01-24·CVSS 9.8
CVE-2021-44515 [CRITICAL] ET EXPLOIT Zoho ManagedEngine Desktop Central Authentication Bypass - File Upload Attempt (CVE-2021-44515)
ET EXPLOIT Zoho ManagedEngine Desktop Central Authentication Bypass - File Upload Attempt (CVE-2021-44515)
Rule: alert http $EXTERNAL_NET any -> $HOME_NET any (msg:"ET EXPLOIT Zoho ManagedEngine Desktop Central Authentication Bypass - File Upload Attempt (CVE-2021-44515)"; flow:established,to_server; http.method; content:"POST"; http.uri; content:"/STATE_ID/"; startswith; content:"/agentLogUploader?"; distance:0; content:"filename="; nocase; distance:0; pcre:"/^[a-zA-Z0-9]+\.(?:zip|7z|gz)/Ri"; content:"branchofficeid="; nocase; http.cookie; content:"STATE_COOKIE="; reference:url,attackerkb.com/topics/rJw4DFI2RQ/cve-2021-44515/rapid7-analysis; reference:cve,2021-44515; classtype:attempted-admin; sid:2034957; rev:2; metadata:created_at 2022_01_24, cve CVE_2021_44515, deployment Perimeter, d
No public exploits indexed.
No writeups or analysis indexed.
2024-12-19
Published