VYPR
Unrated severityNVD Advisory· Published Jun 4, 2020· Updated Aug 4, 2024

CVE-2020-13813

CVE-2020-13813

Description

An issue was discovered in Foxit Studio Photo before 3.6.6.922. It allows local users to gain privileges via a crafted DLL in the current working directory when FoxitStudioPhoto366_3.6.6.916.exe is used.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Foxit Studio Photo before 3.6.6.922 allows local privilege escalation via a crafted DLL in the current working directory.

Vulnerability

Foxit Studio Photo before version 3.6.6.922 is vulnerable to a local privilege escalation due to an insecure dynamic-link library (DLL) loading mechanism. When the installer executable FoxitStudioPhoto366_3.6.6.916.exe is launched, it may load a malicious DLL placed in the current working directory by an attacker. The affected product is Foxit Studio Photo versions prior to 3.6.6.922 [1].

Exploitation

An attacker with local access to the system can exploit this vulnerability by placing a crafted DLL in the directory from which the vulnerable Foxit Studio Photo installer is executed. No additional authentication or user interaction beyond running the installer is required, as the installer will automatically load the malicious DLL if present in the current working directory.

Impact

Successful exploitation allows the attacker to execute arbitrary code in the context of the user running the installer. This can lead to privilege escalation, potentially enabling the attacker to achieve persistence, install programs, or access sensitive data with the victim's privileges.

Mitigation

Foxit has released Foxit Studio Photo version 3.6.6.922 to address this issue. Users should update to this or any later version [1]. No workarounds are described in the available references; the only mitigation is to apply the official update.

AI Insight generated on May 27, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.