Use-After-Free Vulnerability in Acrobat Reader DC: Memory Leak via Annotation Processing

Use-After-Free Vulnerability in Acrobat Reader DC: Memory Leak via Annotation Processing

CVE-2022-28269 · MEDIUM Severity

AV:N/AC:M/AU:N/C:P/I:N/A:N

Acrobat Reader DC versions 22.001.20085 (and earlier), 20.005.3031x (and earlier) and 17.012.30205 (and earlier) are affected by a use-after-free vulnerability in the processing of Annotation objects that could result in a memory leak in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

Learn more about our User Device Pen Test.