CVE-2020-29075: Adobe Acrobat

Medium severity, CVSS 6.5. EPSS: 7.9% chance of exploitation in the next 30 days.

Acrobat Reader DC versions 2020.013.20066 (and earlier), 2020.001.30010 (and earlier) and 2017.011.30180 (and earlier) are affected by an information exposure vulnerability, that could enable an attacker to get a DNS interaction and track if the user has opened or closed a PDF file when loaded from the filesystem without a prompt. User interaction is required to exploit this vulnerability.

Affected products

  • Adobe Acrobat: from 17.011.30059, up to and including 17.011.30180; from 20.001.30005, up to and including 20.001.30010
  • Adobe Acrobat DC: from 15.008.20082, up to and including 20.013.20066
  • Adobe Acrobat Reader: from 17.011.30059, up to and including 17.011.30180; from 20.001.30005, up to and including 20.001.30010
  • Adobe Acrobat Reader DC: from 15.008.20082, up to and including 20.013.20066

Published 2021-02-23. Last modified 2026-06-17.