vciy

Adobe Acrobat Reader: 34 records in one advisory

34 records announced together, published 2022-05-11, every one of them citing the same advisory.

The advisory

Every record in this batch cites https://helpx.adobe.com/security/products/acrobat/apsb22-16.html. That is the CNA's own reference, held in the index, and it is why these records are on one page.

What the records offer

No record in this batch publishes a fixed version in held sources.

No record in this batch is listed by CISA in held sources.

7 of 34 records name something of its own. For the other 27, held sources say the same thing about each.

Most commonly mapped weakness across the batch: CWE-416 Use After Free (CWE-416).

What this page does not cover

This batch is 34 of the 74 records that cite the same advisory. The other 40 are different findings announced alongside it.

28 of them are on the sibling batch linked below. The remaining 12 are grouped with nothing and have only their own record pages.

Other batches under the same advisory: adobe-apsb22-16-3a9b4dfc22

The batch is what one advisory announced. It is not every record sharing this weakness, this product or this mechanism, and nothing here is scoped to any estate.

What this batch was researched, not held

Two annotation findings from the same researcher, reported two weeks apart

This group holds 34 of the 74 records naming Adobe's May 2022 Acrobat and Reader update, all published on 11 May 2022. Two of them can be followed all the way back, because Trend Micro's Zero Day Initiative published its own advisories for them. CVE-2022-28268 is a read past the end of a buffer in the handling of annotation objects, the parts of a document that hold comments, highlights and stamps. CVE-2022-28250 is a use-after-free in the parsing of the same kind of object, where the program acts on an object without first checking it is still there. Both were reported by Mat Powell of the Zero Day Initiative, on 25 February 2022 and 11 March 2022, two weeks apart and into the same area of the program. The Zero Day Initiative published both on 28 April 2022 and both advisories point back to this Adobe update as the fix. Both are rated 3.3 out of 10, which is low: on their own they leak a little memory, and the advisories say an attacker would need to combine one with something else to run code.

These records were published on one day because Adobe ships Reader fixes on a schedule, not because they are one problem. For two of them we can name the researcher, the date he reported it and the part of the program involved. For the other 32 we cannot, and nothing in a record says whether it resembles the two we can.

2022-02-25Mat Powell reports the annotation read past the end of a buffer, later CVE-2022-28268, to Adobe
2022-03-11The same researcher reports the annotation use-after-free, later CVE-2022-28250, two weeks later
2022-04-28The Zero Day Initiative publishes both advisories, each naming this Adobe update as the fix
2022-05-11The 34 records in this group reach the CVE list on one day

The specific gap here is attribution, not description. Adobe's acknowledgements page is not readable to us, so of the 34 records in this group we can name a reporter for two, and only because the Zero Day Initiative published those two itself. Nothing tells you how the other 32 were found, when they were reported, or whether they came from one person or thirty. Nothing here says whether any of them was ever seen in an attack.

Written from zerodayinitiative.com, zerodayinitiative.com, cveawg.mitre.org, cveawg.mitre.org, helpx.adobe.com. Reviewed for whether every claim traces to one of them, by two independent graders, citation support 4.44 of 5, uniqueness 4 of 5. Stated at high confidence. Nothing in this box is a value the index holds, and none of it opens a receipt.

Listed for shared announcement, not shared vulnerability. Each record here is its own finding with its own page, and fixing one does not address another.

CVE-2022-24101Adobe Acrobat Reader DC Annotation Use-After-Free Information Disclosure VulnerabilityCWE-416 Use After Free (CWE-416)
CVE-2022-24102Adobe Acrobat Reader DC Annotation Use-After-Free Remote Code Execution VulnerabilityCWE-416 Use After Free (CWE-416)
CVE-2022-24103Adobe Acrobat Reader DC Annotation Use-After-Free Remote Code Execution VulnerabilityCWE-416 Use After Free (CWE-416)
CVE-2022-24104Adobe Acrobat Reader DC Annotation Use-After-Free Remote Code Execution VulnerabilityCWE-416 Use After Free (CWE-416)
CVE-2022-27785Adobe Acrobat Reader DC Font Parsing Use-After-Free Remote Code Execution VulnerabilityCWE-416 Use After Free (CWE-416)
CVE-2022-27786Adobe Acrobat Reader DC Font Parsing Use-After-Free Remote Code Execution VulnerabilityCWE-416 Use After Free (CWE-416)
CVE-2022-27787Adobe Acrobat Reader DC Font Parsing Out-Of-Bounds Write Remote Code Execution VulnerabilityCWE-787 Out-of-bounds Write (CWE-787)
CVE-2022-27788Adobe Acrobat Reader DC Font Parsing Out-Of-Bounds Write Remote Code Execution VulnerabilityCWE-787 Out-of-bounds Write (CWE-787)
CVE-2022-27789Adobe Acrobat Reader DC AcroForm Use-After-Free Remote Code Execution VulnerabilityCWE-416 Use After Free (CWE-416)
CVE-2022-27790Adobe Acrobat Reader DC Font Parsing Use-After-Free Remote Code Execution VulnerabilityCWE-416 Use After Free (CWE-416)
CVE-2022-27791Adobe Acrobat Reader DC Font Parsing Stack-based Buffer Overflow Remote Code Execution VulnerabilityCWE-121 Stack-based Buffer Overflow (CWE-121)
CVE-2022-27792Adobe Acrobat Reader DC Font Parsing Out-Of-Bounds Write Remote Code Execution VulnerabilityCWE-787 Out-of-bounds Write (CWE-787)
CVE-2022-27793Adobe Acrobat Reader DC Font Parsing Out-Of-Bounds Write Remote Code Execution VulnerabilityCWE-787 Out-of-bounds Write (CWE-787)
CVE-2022-27794Adobe Acrobat Reader DC Font Parsing Uninitialized Variable Remote Code Execution VulnerabilityCWE-824 Access of Uninitialized Pointer…
CVE-2022-27795Adobe Acrobat Reader DC AcroForm isDefaultChecked Use-After-Free Remote Code Execution VulnerabilityCWE-416 Use After Free (CWE-416)
CVE-2022-27796Adobe Acrobat Reader DC AcroForm isBoxChecked Use-After-Free Remote Code Execution VulnerabilityCWE-416 Use After Free (CWE-416)
CVE-2022-27797Adobe Acrobat Reader DC Annotation Use-After-Free Remote Code Execution VulnerabilityCWE-416 Use After Free (CWE-416)
CVE-2022-27798Adobe Acrobat Reader DC zoomType Out-Of-Bounds Write Remote Code Execution VulnerabilityCWE-787 Out-of-bounds Write (CWE-787)
CVE-2022-27799Adobe Acrobat Reader DC AcroForm Use-After-Free Remote Code Execution VulnerabilityCWE-416 Use After Free (CWE-416)
CVE-2022-27800Adobe Acrobat Reader DC Annotation Use-After-Free Remote Code Execution VulnerabilityCWE-416 Use After Free (CWE-416)
CVE-2022-27801Adobe Acrobat Reader DC Annotation Use-After-Free Remote Code Execution VulnerabilityCWE-416 Use After Free (CWE-416)
CVE-2022-27802Adobe Acrobat Reader DC Annotation Use-After-Free Remote Code Execution VulnerabilityCWE-416 Use After Free (CWE-416)
CVE-2022-28230Adobe Acrobat Reader DC AcroForm calculateNow Use-After-Free Remote Code Execution VulnerabilityCWE-416 Use After Free (CWE-416)
CVE-2022-28231Adobe Acrobat Reader DC Doc Object Out-Of-Bounds Read Information Disclosure VulnerabilityCWE-125 Out-of-bounds Read (CWE-125)
CVE-2022-28232Adobe Acrobat Reader DC Collab Object Use-After-Free Information Disclosure VulnerabilityCWE-416 Use After Free (CWE-416)
CVE-2022-28233Adobe Acrobat Reader DC Annotation Use-After-Free Remote Code Execution VulnerabilityCWE-416 Use After Free (CWE-416)
CVE-2022-28234Adobe Acrobat Reader DC Heap Overflow Could Lead to RCECWE-122 Heap-based Buffer Overflow (CWE-122)
CVE-2022-28235Adobe Acrobat Reader DC AcroForm Use-After-Free Remote Code Execution VulnerabilityCWE-416 Use After Free (CWE-416)
CVE-2022-28236Adobe Acrobat Reader DC Annotation Out-Of-Bounds Write Remote Code Execution VulnerabilityCWE-787 Out-of-bounds Write (CWE-787)
CVE-2022-28237Adobe Acrobat Reader DC Annotation Use-After-Free Remote Code Execution VulnerabilityCWE-416 Use After Free (CWE-416)
CVE-2022-28238Adobe Acrobat Reader DC Annotation Use-After-Free Remote Code Execution VulnerabilityCWE-416 Use After Free (CWE-416)
CVE-2022-28244Adobe Acrobat Reader DC CSP Bypass Leads To Privilege EscalationCWE-657 Violation of Secure Design Principles…
CVE-2022-28268Adobe Acrobat Reader DC Annotation Out-Of-Bounds Read Information Disclosure VulnerabilityCWE-125 Out-of-bounds Read (CWE-125)
CVE-2022-28269Adobe Acrobat Reader DC Annotation Use-After-Free Information Disclosure VulnerabilityCWE-416 Use After Free (CWE-416)

34 records, read from the index as it stood on 2026-09-20. Every row opens the record it names, and every value on that record opens its own receipt.

Everything on this page is free. Public data. Withholding it protects nothing.