CVE-2022-28244: medium-severity vulnerability in Adobe Acrobat Reader
Adobe Acrobat Reader DC CSP Bypass Leads To Privilege Escalation
Published · Updated
No sign of exploitation. No public exploitation artifact known so far.
Adobe Acrobat Reader DC has a flaw that allows attackers to bypass security policies designed to prevent unauthorized cross-origin requests. An attacker can trick a user into opening a malicious PDF file, which then sends unwanted requests to other websites on behalf of the victim.
CVE-2022-28244 involves a Content Security Policy (CSP) bypass in Acrobat Reader DC through violation of secure design principles. The attack vector requires user interaction (opening a crafted PDF from an attacker-controlled server) and allows execution of arbitrary cross-origin requests. The impact enables unauthorized actions against third-party domains in the victim's security context.
In the same product, most dangerous first.