IT

Tracker / CVE-2020-29075

CVE-2020-29075

High 7.1

Acrobat Reader DC versions 2020.013.20066 (and earlier), 2020.001.30010 (and earlier) and 2017.011.30180 (and earlier) are affected by an information exposure vulnerability, that could enable an attacker to get a DNS interaction and track if the user has opened or closed a PDF file when loaded from the filesystem without a prompt. User interaction is required to exploit this vulnerability.

Affected products and versions

adobe acrobat · 17.011.30059 → 17.011.30180
adobe acrobat · 20.001.30005 → 20.001.30010
adobe acrobat_dc · 15.008.20082 → 20.013.20066
adobe acrobat_reader · 17.011.30059 → 17.011.30180
adobe acrobat_reader · 20.001.30005 → 20.001.30010
adobe acrobat_reader_dc · 15.008.20082 → 20.013.20066

Analysis

This page is not indexable yet.Until it carries original analysis — what it actually exposes, how to check in two minutes whether a system was touched, what to do if it was — the page stays noindex. The database decides that, not the template.

References