CVE-2022-44519
published 2024-12-19CVE-2022-44519: Acrobat Reader DC version 22.001.20085 (and earlier), 20.005.3031x (and earlier) and 17.012.30205 (and earlier) are affected by a use-after-free vulnerability…
PriorityP426medium5.5CVSS 3.1
AVLACLPRNUIRSUCHINAN
EPSS
0.29%
20.8th percentile
Acrobat Reader DC version 22.001.20085 (and earlier), 20.005.3031x (and earlier) and 17.012.30205 (and earlier) are affected by a use-after-free vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Affected
9 ranges
| Vendor | Product | Version range | Fixed in |
|---|---|---|---|
| adobe | acrobat | 17.011.30059 – 17.012.30205 | — |
| adobe | acrobat | 20.001.30005 – 20.005.30314 | — |
| adobe | acrobat | 20.001.30005 – 20.005.30311 | — |
| adobe | acrobat_dc | 15.008.20082 – 22.001.20085 | — |
| adobe | acrobat_reader | <= 17.012.30205 | — |
| adobe | acrobat_reader | 17.011.30059 – 17.012.30205 | — |
| adobe | acrobat_reader | 20.001.30005 – 20.005.30314 | — |
| adobe | acrobat_reader | 20.001.30005 – 20.005.30311 | — |
| adobe | acrobat_reader_dc | 15.008.20082 – 22.001.20085 | — |
Stop checking back — get the weekly exploitation signal.
Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.
GHSA
GHSA-h6p8-mv4f-g96v: Acrobat Reader DC version 22
ghsa_unreviewed·2024-12-19
CVE-2022-44519 [MEDIUM] CWE-416 GHSA-h6p8-mv4f-g96v: Acrobat Reader DC version 22
Acrobat Reader DC version 22.001.20085 (and earlier), 20.005.3031x (and earlier) and 17.012.30205 (and earlier) are affected by a use-after-free vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
Citrix
Citrix Endpoint Management (XenMobile Server) Security Bulletin for CVE-2021-44519, CVE-2021-44520, and CVE-2022-26151
vendor_citrix·CVSS 8.8
CVE-2021-44519 [HIGH] CWE-20 Citrix Endpoint Management (XenMobile Server) Security Bulletin for CVE-2021-44519, CVE-2021-44520, and CVE-2022-26151
Citrix Endpoint Management (XenMobile Server) Security Bulletin for CVE-2021-44519, CVE-2021-44520, and CVE-2022-26151
CWE Pre-conditions CVE-2021-44519 Unauthorized access to the underlying OS CWE-284: Improper Access Control A XenMobile console user must have either an admin role or a custom role that has ‘Create Support Bundles’ enabled. These permissions can only be assigned by an admin user. CVE-2021-44520 Unauthorized root access to the underlying OS CWE-284: Improper Access Control Access to the underlying OS CVE-2022-26151 Unauthorized root access to the underlying OS CWE-20: Improper Input Validation Admin access to XenMobile Server CLI The issues affect the following supported versions of Citrix Endpoint Management (XenMobile Server) CVE-2021-44519, CVE-2021-44520 - Medium sever
No detection rules found.
No public exploits indexed.
No writeups or analysis indexed.
2024-12-19
Published