Vulnerability Description
Acrobat Reader DC version 22.001.20085 (and earlier), 20.005.3031x (and earlier) and 17.012.30205 (and earlier) are affected by an out-of-bounds read vulnerability when parsing a crafted file, which could result in a read past the end of an allocated memory structure. An attacker could leverage this vulnerability to bypass mitigations such as ASLR. Exploitation of this issue requires user interaction in that a victim must open a malicious file.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Adobe | Acrobat | >= 17.011.30059, < 17.012.30229 |
| Adobe | Acrobat Dc | >= 22.001.20085, < 22.001.20117 |
| Adobe | Acrobat Reader | >= 17.011.30059, < 17.012.30229 |
| Adobe | Acrobat Reader Dc | >= 22.001.20085, < 22.001.20117 |
| Microsoft | Windows | - |
| Apple | Macos | - |
Related Weaknesses (CWE)
References
FAQ
What is CVE-2022-44517?
CVE-2022-44517 is a vulnerability with a CVSS score of 5.5 (MEDIUM). Acrobat Reader DC version 22.001.20085 (and earlier), 20.005.3031x (and earlier) and 17.012.30205 (and earlier) are affected by an out-of-bounds read vulnerability when parsing a crafted file, which c...
How severe is CVE-2022-44517?
CVE-2022-44517 has been rated MEDIUM with a CVSS base score of 5.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2022-44517?
Check the references section above for vendor advisories and patch information. Affected products include: Adobe Acrobat, Adobe Acrobat Dc, Adobe Acrobat Reader, Adobe Acrobat Reader Dc, Microsoft Windows.