Use-After-Free Vulnerability in Acrobat Reader DC: Arbitrary Code Execution

Use-After-Free Vulnerability in Acrobat Reader DC: Arbitrary Code Execution

CVE-2022-28237 · HIGH Severity

AV:N/AC:M/AU:N/C:C/I:C/A:C

Acrobat Reader DC versions 22.001.20085 (and earlier), 20.005.3031x (and earlier) and 17.012.30205 (and earlier) are affected by a use-after-free vulnerability in the processing of annotations that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

Learn more about our User Device Pen Test.