Out-of-bounds write in Adobe Reader and Adobe Acrobat - CVE-2022-35667

 

Out-of-bounds write in Adobe Reader and Adobe Acrobat - CVE-2022-35667

Published: August 10, 2022 / Updated: August 19, 2022


Vulnerability identifier: #VU66335
CSH Severity: High
CVSS v4: 8.4 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2022-35667
CWE-ID: CWE-787
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to compromise vulnerable system.

The vulnerability exists due to a boundary error when parsing embedded fonts. A remote attacker can trick the victim to open a specially crafted PDF file, trigger an out-of-bounds write and execute arbitrary code on the system.

Successful exploitation of the vulnerability may allow an attacker to compromise vulnerable system.


Affected software

Adobe Reader
Adobe Acrobat

How to mitigate CVE-2022-35667

Install updates from vendor's website.

Adobe Reader - addressed in versions 17.012.30262, 20.005.30381, 22.002.20191
Adobe Acrobat - addressed in versions 17.012.30262, 20.005.30381, 22.002.20191

External References

Related Security Bulletins