Vulnerability Database

290,278

Total vulnerabilities in the database

CVE-2022-27801

Acrobat Reader DC versions 22.001.20085 (and earlier), 20.005.3031x (and earlier) and 17.012.30205 (and earlier) are affected by a use-after-free vulnerability in the processing of annotations that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

  • Published: May 11, 2022
  • Updated: Apr 14, 2023
  • CVE: CVE-2022-27801
  • Severity: High
  • Exploit:

CVSS v2:

  • Severity: High
  • Score: 9.3
  • AV:N/AC:M/Au:N/C:C/I:C/A:C

CWEs:

Software From Fixed in
adobe / acrobat_dc 15.008.20082 22.001.20085.x
adobe / acrobat_reader_dc 15.008.20082 22.001.20085.x
adobe / acrobat 17.011.30059 17.012.30205.x
adobe / acrobat_reader 17.011.30059 17.012.30205.x
adobe / acrobat 20.001.30005 20.005.30314.x
adobe / acrobat_reader 20.001.30005 20.005.30314.x
adobe / acrobat 20.001.30005 20.005.30311.x
adobe / acrobat_reader 20.001.30005 20.005.30311.x