Rewterz
Rewterz Threat Alert – Cobalt Strike Malware – Active IOCs
July 29, 2022
Rewterz
Rewterz Threat Alert – Mirai Botnet – Active IOCs
July 29, 2022

Rewterz Threat Advisory – Multiple Adobe Acrobat and Adobe Reader Vulnerabilities

Severity

Medium

Analysis Summary

CVE-2022-35669 CVSS:5.5

Adobe Acrobat and Adobe Reader could allow a remote attacker to obtain sensitive information, caused by an out-of-bounds read vulnerability. By persuading a victim to open a specially-crafted document, a remote attacker could exploit this vulnerability to obtain sensitive information.

CVE-2022-35672 CVSS:7.8

Adobe Acrobat and Adobe Reader could allow a remote attacker to execute arbitrary code on the system, caused by an out-of-bounds read vulnerability. By persuading a victim to open a specially-crafted document, a remote attacker could exploit this vulnerability to execute code on the system with the privileges of the victim.

Impact

  • Information Disclosure

Indicators Of Compromise

CVE

  • CVE-2022-35669
  • CVE-2022-35672

Affected Vendors

Adobe

Affected Products

Adobe Acrobat 2017 17.012.30229
Adobe Acrobat Reader 2017 17.012.30229
Adobe Acrobat Reader 2020 20.005.30334
Adobe Acrobat Reader 2017 17.012.30227
Adobe Acrobat 2017 17.012.30227
Adobe Acrobat Reader 2020 20.005.30331
Adobe Acrobat 2020 20.005.30331
Adobe Acrobat 2020 20.005.30334
Adobe Acrobat DC 22.001.20142
Adobe Acrobat Reader DC 22.001.20142

Remediation

Refer to Adobe Security Advisory for patch, upgrade or suggested workaround information.

Adobe Security Advisory