CVE-2020-29075 - CVE House
Back to Database
Status published High CVE-2020-29075

PDF Injection BlackHat Talk

Vulnerability Description

Acrobat Reader DC versions 2020.013.20066 (and earlier), 2020.001.30010 (and earlier) and 2017.011.30180 (and earlier) are affected by an information exposure vulnerability, that could enable an attacker to get a DNS interaction and track if the user has opened or closed a PDF file when loaded from the filesystem without a prompt. User interaction is required to exploit this vulnerability.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2020-29075

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Affected Software

Acrobat Reader DC
Vulnerable Versions:
<= 2020.013.20066, <= 2020.001.30010, <= 2017.011.30180

Timeline

Official Publish: February 23rd, 2021
Last Modified: September 16th, 2024
Added to House: July 21st, 2026

CVSS Vectors

V3: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:L/A:N

Weaknesses (CWE)