cbcvebase.
CVE-2022-44517
published 2024-12-19

CVE-2022-44517: Acrobat Reader DC version 22.001.20085 (and earlier), 20.005.3031x (and earlier) and 17.012.30205 (and earlier) are affected by an out-of-bounds read…

medium5.5CVSS 3.1
AVLACLPRNUIRSUCHINAN
Acrobat Reader DC version 22.001.20085 (and earlier), 20.005.3031x (and earlier) and 17.012.30205 (and earlier) are affected by an out-of-bounds read vulnerability when parsing a crafted file, which could result in a read past the end of an allocated memory structure. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

Affected

13 ranges
VendorProductVersion rangeFixed in
adobeacrobat>= 17.011.30059 < 17.012.3022917.012.30229
adobeacrobat>= 17.011.30059 < 17.012.3022717.012.30227
adobeacrobat>= 20.001.30002 < 20.005.3033420.005.30334
adobeacrobat>= 20.001.30002 < 20.005.3033120.005.30331
adobeacrobat_dc>= 22.001.20085 < 22.001.2011722.001.20117
adobeacrobat_dc>= 22.001.20085 < 22.001.2011222.001.20112
adobeacrobat_reader<= 17.012.30205
adobeacrobat_reader>= 17.011.30059 < 17.012.3022917.012.30229
adobeacrobat_reader>= 17.011.30059 < 17.012.3022717.012.30227
adobeacrobat_reader>= 20.001.30002 < 20.005.3033420.005.30334
adobeacrobat_reader>= 20.001.30002 < 20.005.3033120.005.30331
adobeacrobat_reader_dc>= 22.001.20085 < 22.001.2011722.001.20117
adobeacrobat_reader_dc>= 22.001.20085 < 22.001.2011222.001.20112