CVE-2020-29075
Last modified
CVE-2020-29075 is a medium-severity vulnerability rated 6.5/10 on the CVSS scale. Acrobat Reader DC versions 2020.013.20066 (and earlier), 2020.001.30010 (and earlier) and 2017.011.30180 (and earlier) are affected by an information exposure vulnerability, that could enable an attacker to get a DNS interaction and track if the user has opened or closed a PDF file when loaded from the filesystem without a prompt. User interaction is required to exploit this vulnerability.. EPSS estimates a 7.82% chance of exploitation in the next 30 days.
Description
Acrobat Reader DC versions 2020.013.20066 (and earlier), 2020.001.30010 (and earlier) and 2017.011.30180 (and earlier) are affected by an information exposure vulnerability, that could enable an attacker to get a DNS interaction and track if the user has opened or closed a PDF file when loaded from the filesystem without a prompt. User interaction is required to exploit this vulnerability.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Adobe | Acrobat | >= 17.011.30059, <= 17.011.30180 |
| Adobe | Acrobat | >= 20.001.30005, <= 20.001.30010 |
| Adobe | Acrobat Dc | >= 15.008.20082, <= 20.013.20066 |
| Adobe | Acrobat Reader | >= 17.011.30059, <= 17.011.30180 |
| Adobe | Acrobat Reader | >= 20.001.30005, <= 20.001.30010 |
| Adobe | Acrobat Reader Dc | >= 15.008.20082, <= 20.013.20066 |
References
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2020-29075?
How severe is CVE-2020-29075?
How do I fix CVE-2020-29075?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2020
- CVE-2020-29069_get_flag_ip_localdb in server/mhn/ui/utils.py in Modern Hon…5.5
- CVE-2020-2907Vulnerability in the Oracle VM VirtualBox product of Oracle …7.5
- CVE-2020-29070osCommerce 2.3.4.1 has XSS vulnerability via the authenticat…4.8
- CVE-2020-29071An XSS issue was found in the Shares feature of LiquidFiles …9
- CVE-2020-29072A Cross-Site Script Inclusion vulnerability was found on Liq…6.1
- CVE-2020-29074scan.c in x11vnc 0.9.16 uses IPC_CREAT|0777 in shmget calls,…8.8
- CVE-2020-2908Vulnerability in the Oracle VM VirtualBox product of Oracle …8.2
- CVE-2020-2909Vulnerability in the Oracle VM VirtualBox product of Oracle …2.8
- CVE-2020-2910Vulnerability in the Oracle VM VirtualBox product of Oracle …6.5
- CVE-2020-2911Vulnerability in the Oracle VM VirtualBox product of Oracle …7.5
- CVE-2020-2912Vulnerability in the PeopleSoft Enterprise CS Campus Communi…5
- CVE-2020-29127An issue was discovered on Fujitsu Eternus Storage DX200 S4 …9.8
Are you affected by CVE-2020-29075?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
