VYPR
Unrated severityNVD Advisory· Published Jun 3, 2019· Updated Aug 4, 2024

CVE-2019-6748

CVE-2019-6748

Description

This vulnerability allows remote attackers to execute arbitrary code on vulnerable installations of Foxit Studio Photo 3.6.6. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of EZI files. The issue results from the lack of proper validation of user-supplied data, which can result in a write past the end of an allocated structure. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-7637.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Foxit Studio Photo 3.6.6 fails to validate EZI file data, causing a heap out-of-bounds write that can be leveraged for remote code execution with user interaction.

Vulnerability

Foxit Studio Photo version 3.6.6 contains an out-of-bounds write vulnerability in the handling of EZI files. The issue stems from improper validation of user-supplied data, leading to a write past the end of an allocated structure. This flaw is reachable when the user opens a malicious EZI file or visits a page that triggers file parsing. [2]

Exploitation

An attacker must convince the target to open a specially crafted EZI file or navigate to a malicious page that triggers file handling. No prior authentication is required. The attacker can control the data that causes the out-of-bounds write, enabling arbitrary code execution within the context of the current process. [2]

Impact

Successful exploitation allows an attacker to execute arbitrary code in the context of the Foxit Studio Photo process, potentially compromising the user's system. The CVSS score is 7.8, reflecting high impact on confidentiality, integrity, and availability. [2]

Mitigation

No official patch was available at the time of publication (June 2019) according to the ZDI advisory. Users should restrict access to untrusted EZI files and consider upgrading to a newer version of Foxit Studio Photo if a fix becomes available. [2]

References
  1. ZDI-19-372

AI Insight generated on May 26, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

2

News mentions

0

No linked articles in our index yet.