CVE-2019-13325
Description
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit Studio Photo 3.6.6.909. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of EPS files. The issue results from the lack of proper validation of user-supplied data, which can result in a read past the end of an allocated structure. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-8922.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Foxit Studio Photo 3.6.6.909 fails to validate EPS file data, allowing a heap out-of-bounds read that can lead to remote code execution via user interaction.
Vulnerability
The vulnerability resides in the handling of Encapsulated PostScript (EPS) files within Foxit Studio Photo version 3.6.6.909. The specific flaw is a lack of proper validation of user-supplied data, resulting in an out-of-bounds read past the end of an allocated structure [2]. No special configuration is required to reach the vulnerable code path; any user who opens a crafted EPS file in the affected version triggers the parsing routine.
Exploitation
To exploit this vulnerability, an attacker must convince a user to visit a malicious webpage or open a malicious EPS file [2]. The attack vector is remote, but user interaction is required. No authentication or special privileges are needed on the target system. If the user opens the crafted EPS file, the application will read beyond the bounds of an allocated heap structure, which an attacker can leverage to achieve code execution [1][2].
Impact
Successful exploitation allows the attacker to execute arbitrary code within the context of the Foxit Studio Photo process [2]. The CVSS v3 score is 7.8 (High) with an impact vector indicating complete compromise of Confidentiality, Integrity, and Availability (C:H/I:H/A:H) [2]. The attacker gains the same privileges as the current user, which could lead to further system compromise if that user has elevated rights.
Mitigation
As of the publication date (2019-10-03), Foxit had not yet released a fixed version for Foxit Studio Photo specifically; the vendor's security bulletin page at the time primarily addressed Foxit PDF Reader and Foxit PDF Editor [1]. The Zero Day Initiative advisory [2] recommends users apply any vendor-provided updates when they become available. No workarounds are documented. Users should restrict opening EPS files from untrusted sources and monitor Foxit's security bulletins for a patch.
AI Insight generated on May 26, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
2- Range: = 3.6.6.909
- Foxit/Studio Photov5Range: 3.6.6.909
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
2- www.foxitsoftware.com/support/security-bulletins.phpmitrex_refsource_MISC
- www.zerodayinitiative.com/advisories/ZDI-19-842/mitrex_refsource_MISC
News mentions
0No linked articles in our index yet.