HTTP: Adobe Acrobat and Acrobat Reader DNS Lookup Information Disclosure

This signature detects attempts to exploit a known vulnerability against Adobe Acrobat and Acrobat Reader. A successful attack can lead to sensitive information disclosure.

Extended Description

Acrobat Reader DC versions 2020.013.20066 (and earlier), 2020.001.30010 (and earlier) and 2017.011.30180 (and earlier) are affected by an information exposure vulnerability, that could enable an attacker to get a DNS interaction and track if the user has opened or closed a PDF file when loaded from the filesystem without a prompt. User interaction is required to exploit this vulnerability.

References

CVE: CVE-2020-29075

Short Name
HTTP:STC:ADOBE:DNS-INFO-DISC
Severity
Minor
Recommended
True
Recommended Action
Drop
Category
HTTP
Keywords
Acrobat Adobe CVE-2020-29075 DNS Disclosure Information Lookup Reader and
Release Date
12/17/2020
Supported Platforms

srx-branch-12.3

srx-19.3

srx-branch-19.3

vsrx3bsd-19.2

srx-branch-19.4

vsrx-19.4

mx-12.3

mx-19.4

vmx-19.4

mx-19.3

vsrx3bsd-19.4

srx-19.4

vsrx-12.3

vmx-19.3

vsrx-19.2

srx-12.3

Sigpack Version
3377
False Positive
Unknown
CVSS Score

4.3

Found a potential security threat?