9.3

CVE-2022-27794

Adobe Acrobat Reader DC Font Parsing Uninitialized Variable Remote Code Execution Vulnerability

Acrobat Reader DC versions 22.001.20085 (and earlier), 20.005.3031x (and earlier) and 17.012.30205 (and earlier) is affected by the use of a variable that has not been initialized when processing of embedded fonts, potentially resulting in arbitrary code execution in the context of the current user. Exploitation requires user interaction in that a victim must open a crafted .pdf file
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
AdobeAcrobat Dc SwEditioncontinuous Version >= 15.008.20082 <= 22.001.20085
   ApplemacOS Version-
   MicrosoftWindows Version-
AdobeAcrobat Reader Dc SwEditioncontinuous Version >= 15.008.20082 <= 22.001.20085
   ApplemacOS Version-
   MicrosoftWindows Version-
AdobeAcrobat SwEditionclassic Version >= 17.011.30059 <= 17.012.30205
   ApplemacOS Version-
   MicrosoftWindows Version-
AdobeAcrobat Reader SwEditionclassic Version >= 17.011.30059 <= 17.012.30205
   ApplemacOS Version-
   MicrosoftWindows Version-
AdobeAcrobat SwEditionclassic Version >= 20.001.30005 <= 20.005.30314
   MicrosoftWindows Version-
AdobeAcrobat Reader SwEditionclassic Version >= 20.001.30005 <= 20.005.30314
   MicrosoftWindows Version-
AdobeAcrobat SwEditionclassic Version >= 20.001.30005 <= 20.005.30311
   ApplemacOS Version-
AdobeAcrobat Reader SwEditionclassic Version >= 20.001.30005 <= 20.005.30311
   ApplemacOS Version-
Zu dieser CVE wurde keine Warnung gefunden.
EPSS Metriken
Typ Quelle Score Percentile
EPSS FIRST.org 1.19% 0.782
CVSS Metriken
Quelle Base Score Exploit Score Impact Score Vector String
nvd@nist.gov 7.8 1.8 5.9
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvd@nist.gov 9.3 8.6 10
AV:N/AC:M/Au:N/C:C/I:C/A:C
psirt@adobe.com 7.8 1.8 5.9
CVSS:3.0/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
CWE-824 Access of Uninitialized Pointer

The product accesses or uses a pointer that has not been initialized.