ZeroHour

CVE-2020-29075

CVSS 3.1
6.5 medium
EPSS
8%p94
Published
()
Modified
Description

Acrobat Reader DC versions 2020.013.20066 (and earlier), 2020.001.30010 (and earlier) and 2017.011.30180 (and earlier) are affected by an information exposure vulnerability, that could enable an attacker to get a DNS interaction and track if the user has opened or closed a PDF file when loaded from the filesystem without a prompt. User interaction is required to exploit this vulnerability.

Vendors
adobe
Products
acrobat, acrobat dc, acrobat reader, acrobat reader dc
Weakness
CWE-20, CWE-200
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N

In the news