CVE-2020-29075
HIGHAdobe Acrobat/Reader DC < 20.013.20066 & < 17.011.30180 - DNS Info Exposure
Title source: llmDescription
Acrobat Reader DC versions 2020.013.20066 (and earlier), 2020.001.30010 (and earlier) and 2017.011.30180 (and earlier) are affected by an information exposure vulnerability, that could enable an attacker to get a DNS interaction and track if the user has opened or closed a PDF file when loaded from the filesystem without a prompt. User interaction is required to exploit this vulnerability.
References (1)
Core 1
Core References
Vendor Advisory x_refsource_confirm
https://helpx.adobe.com/security/products/acrobat/apsb20-75.html
Scores
CVSS v3
7.1
EPSS
0.0782
EPSS Percentile
93.9%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:L/A:N
Details
CWE
CWE-20
CWE-200
Status
published
Products (4)
adobe/acrobat
17.011.30059 - 17.011.30180
adobe/acrobat_dc
15.008.20082 - 20.013.20066
adobe/acrobat_reader
17.011.30059 - 17.011.30180
adobe/acrobat_reader_dc
15.008.20082 - 20.013.20066
Published
Feb 23, 2021
Tracked Since
Feb 18, 2026