CVE-2022-28244
Published: 11 May 2022
Summary
CVE-2022-28244 is a medium-severity Violation of Secure Design Principles (CWE-657) vulnerability in Apple Macos. Its CVSS base score is 6.3 (Medium).
Operationally, ranked in the top 13.7% of CVEs by exploit likelihood; it is not currently listed in the CISA KEV catalog.
EU & UK References
- 🇪🇺 ENISA EUVD: EUVD-2022-32696
Vulnerability details
Acrobat Reader DC versions 22.001.20085 (and earlier), 20.005.3031x (and earlier) and 17.012.30205 (and earlier) is affected by a violation of secure design principles through bypassing the content security policy, which could result in an attacker sending arbitrarily configured requests to…
more
the cross-origin attack target domain. Exploitation requires user interaction in which the victim needs to access a crafted PDF file on an attacker's server.
- CWE(s)
Related Threats
No named actor attribution yet. ATT&CK technique mapping in progress for this CVE.
Affected Assets
Mitigating Controls
Likely Mitigating Controls AI
Per-CVE control mapping for this CVE has not run yet; the list below is derived from the weakness types (CWEs) cited in the NVD entry.
Establishing and updating awareness policy promotes adherence to secure design principles through ongoing training, preventing related violations.
Mandating the policy be consistent with laws, standards, and guidelines enforces secure design principles in security governance and oversight.
Deficiencies violating secure design principles are tracked and corrected through planned actions, limiting attacker opportunities from design flaws.
Documenting, disseminating, and periodically reviewing maintenance policies and procedures enforces core secure design principles for system maintenance activities.
Documented policy with defined scope, roles, responsibilities, and periodic review directly enforces secure design principles and management commitment.
Baseline selection enforces adherence to established secure-design principles rather than ad-hoc or insufficient control choices.
Requires risk determinations for architecture/design decisions, tailoring rationale, and alignment with enterprise architecture to avoid violations of secure design principles.
Regular SSP updates force review of whether the system's evolving design continues to follow documented secure design principles after changes.