Remote Information Disclosure Vulnerability in Foxit Studio Photo by Foxit Software
CVE-2020-17433
3.3LOW
Summary
This vulnerability enables remote attackers to disclose sensitive information on installations of Foxit Studio Photo version 3.6.6.922. Exploitation necessitates user interaction, requiring the target to visit a malicious webpage or open a compromised file. The flaw lies in the parsing of CMP files due to inadequate validation of user-supplied data, which can lead to reading past the end of an allocated memory structure. Attackers may combine this vulnerability with others to potentially execute arbitrary code within the context of the affected process. For more information, refer to the Foxit Software security bulletins and Zero Day Initiative advisory.
Affected Version(s)
Studio Photo 3.6.6.922
References
CVSS V3.1
Score:
3.3
Severity:
LOW
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
Required
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
Mat Powell of Trend Micro Zero Day Initiative