Acrobat Reader DC versions 2020.013.20066 (and earlier), 2020.001.30010 (and earlier) and 2017.011.30180 (and earlier) are affected by an information exposure vulnerability, that could enable an attacker to get a DNS interaction and track if the user has opened or closed a PDF file when loaded from the filesystem without a prompt. User interaction is required to exploit this vulnerability.
2021-02-23T04:15:13.960
2024-11-21T05:23:38.690
Modified
CVSSv3.1: 7.1 (HIGH)
AV:N/AC:M/Au:N/C:P/I:N/A:N
8.6
2.9
Type | Vendor | Product | Version/Range | Vulnerable? |
---|---|---|---|---|
Application | adobe | acrobat | ≤ 17.011.30180 | Yes |
Application | adobe | acrobat | ≤ 20.001.30010 | Yes |
Application | adobe | acrobat_dc | ≤ 20.013.20066 | Yes |
Application | adobe | acrobat_reader | ≤ 17.011.30180 | Yes |
Application | adobe | acrobat_reader | ≤ 20.001.30010 | Yes |
Application | adobe | acrobat_reader_dc | ≤ 20.013.20066 | Yes |
Operating System | apple | macos | - | No |
Operating System | microsoft | windows | - | No |