CERT-In Vulnerability Note
CIVN-2020-0439
Information Disclosure Vulnerability in Adobe Acrobat Reader
Original Issue Date:December 17, 2020
Severity Rating: HIGH
Software Affected
- Acrobat DC version 2020.013.20066 and earlier versions for Windows &macOS
- Acrobat Reader DC version 2020.013.20066 and earlier versions for Windows &macOS
- Acrobat 2020 version 2020.001.30010 and earlier versions for Windows &macOS
- Acrobat Reader 2020 version 2020.001.30010 and earlier versions for Windows &macOS
- Acrobat 2017 version 2017.011.30180 and earlier versions for Windows &macOS
- Acrobat Reader 2017 version 2017.011.30180 and earlier versions for Windows &macOS
Overview
A vulnerability has been reported in Adobe Acrobat Reader which could allow a remote attacker to access sensitive information of the targeted system.
Description
A remote attacker could exploit this vulnerability by sending a specially crafted PDF file.
Successful exploitation of this vulnerability could allow remote attacker to gain access sensitive information in the context of the current user.
Solution
Update to latest versions as available at the following URLs:
https://helpx.adobe.com/security/products/acrobat/apsb20-75.html
Vendor Information
Adobe
https://helpx.adobe.com/security/products/acrobat/apsb20-75.html
References
Adobe
https://helpx.adobe.com/security/products/acrobat/apsb20-75.html
CVE Name
CVE-2020-29075
Disclaimer
The information provided herein is on "as is" basis, without warranty of any kind.
Contact Information
Email: info@cert-in.org.in Phone: +91-11-24368572
Postal address
Indian Computer Emergency Response Team (CERT-In) Ministry of Electronics and Information Technology Government of India Electronics Niketan 6, CGO Complex, Lodhi Road, New Delhi - 110 003 India
|