CVE-2020-13813
Description
An issue was discovered in Foxit Studio Photo before 3.6.6.922. It allows local users to gain privileges via a crafted DLL in the current working directory when FoxitStudioPhoto366_3.6.6.916.exe is used.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Foxit Studio Photo before 3.6.6.922 allows local privilege escalation via a crafted DLL in the current working directory.
Vulnerability
Foxit Studio Photo before version 3.6.6.922 is vulnerable to a local privilege escalation due to an insecure dynamic-link library (DLL) loading mechanism. When the installer executable FoxitStudioPhoto366_3.6.6.916.exe is launched, it may load a malicious DLL placed in the current working directory by an attacker. The affected product is Foxit Studio Photo versions prior to 3.6.6.922 [1].
Exploitation
An attacker with local access to the system can exploit this vulnerability by placing a crafted DLL in the directory from which the vulnerable Foxit Studio Photo installer is executed. No additional authentication or user interaction beyond running the installer is required, as the installer will automatically load the malicious DLL if present in the current working directory.
Impact
Successful exploitation allows the attacker to execute arbitrary code in the context of the user running the installer. This can lead to privilege escalation, potentially enabling the attacker to achieve persistence, install programs, or access sensitive data with the victim's privileges.
Mitigation
Foxit has released Foxit Studio Photo version 3.6.6.922 to address this issue. Users should update to this or any later version [1]. No workarounds are described in the available references; the only mitigation is to apply the official update.
AI Insight generated on May 27, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
2- Foxit/Studio Photodescription
- Range: <3.6.6.922
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1- www.foxitsoftware.com/support/security-bulletins.phpmitrex_refsource_CONFIRM
News mentions
0No linked articles in our index yet.