Remote Code Execution Vulnerability in Foxit Studio Photo by Foxit Software
CVE-2020-17431

7.8HIGH

Key Information:

Vendor
Foxit
Vendor
CVE Published:
9 February 2021

Summary

A security vulnerability exists in Foxit Studio Photo 3.6.6.922 that enables remote attackers to execute arbitrary code. The flaw arises from inadequate validation of user-supplied data during the parsing of CR2 files. To exploit this vulnerability, an attacker must convince a user to open a malicious file or visit a harmful webpage, allowing them to write past an allocated structure's end within the application. This could potentially lead to unauthorized code execution in the context of the current process, exposing users to severe risks.

Affected Version(s)

Studio Photo 3.6.6.922

References

CVSS V3.1

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Mat Powell of Trend Micro Zero Day Initiative
.