CVE-2022-44517
published 2024-12-19CVE-2022-44517: Acrobat Reader DC version 22.001.20085 (and earlier), 20.005.3031x (and earlier) and 17.012.30205 (and earlier) are affected by an out-of-bounds read…
medium5.5CVSS 3.1
AVLACLPRNUIRSUCHINAN
Acrobat Reader DC version 22.001.20085 (and earlier), 20.005.3031x (and earlier) and 17.012.30205 (and earlier) are affected by an out-of-bounds read vulnerability when parsing a crafted file, which could result in a read past the end of an allocated memory structure. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Affected
13 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| adobe | acrobat | >= 17.011.30059 < 17.012.30229 | 17.012.30229 |
| adobe | acrobat | >= 17.011.30059 < 17.012.30227 | 17.012.30227 |
| adobe | acrobat | >= 20.001.30002 < 20.005.30334 | 20.005.30334 |
| adobe | acrobat | >= 20.001.30002 < 20.005.30331 | 20.005.30331 |
| adobe | acrobat_dc | >= 22.001.20085 < 22.001.20117 | 22.001.20117 |
| adobe | acrobat_dc | >= 22.001.20085 < 22.001.20112 | 22.001.20112 |
| adobe | acrobat_reader | <= 17.012.30205 | — |
| adobe | acrobat_reader | >= 17.011.30059 < 17.012.30229 | 17.012.30229 |
| adobe | acrobat_reader | >= 17.011.30059 < 17.012.30227 | 17.012.30227 |
| adobe | acrobat_reader | >= 20.001.30002 < 20.005.30334 | 20.005.30334 |
| adobe | acrobat_reader | >= 20.001.30002 < 20.005.30331 | 20.005.30331 |
| adobe | acrobat_reader_dc | >= 22.001.20085 < 22.001.20117 | 22.001.20117 |
| adobe | acrobat_reader_dc | >= 22.001.20085 < 22.001.20112 | 22.001.20112 |