CVE-2020-17404
Description
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit Studio Photo 3.6.6.922. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of PSD files. The issue results from the lack of proper validation of user-supplied data, which can result in a write past the end of an allocated structure. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-11191.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Foxit Studio Photo 3.6.6.922 contains an out-of-bounds write vulnerability in PSD file parsing, allowing remote code execution via a malicious file.
Vulnerability
This vulnerability resides in Foxit Studio Photo version 3.6.6.922. The specific flaw exists within the handling of PSD files. The issue results from the lack of proper validation of user-supplied data, which can result in a write past the end of an allocated structure. No special configuration is required; the affected code path is reachable when any user opens a crafted PSD file. Affected version: Foxit Studio Photo 3.6.6.922 [1][2].
Exploitation
An attacker must convince the target user to visit a malicious page or open a malicious PSD file. User interaction is required [2]. No authentication or special network position is needed, as the attack can be delivered via a website or email attachment. The out-of-bounds write occurs during parsing of the malformed PSD data, which can be triggered by simply opening the file in the application [2].
Impact
Successful exploitation allows the attacker to execute arbitrary code in the context of the current process. This can lead to full compromise of the affected system, including disclosure, modification, or destruction of data, and further propagation. The CVSS v3.1 score is 7.8 (High) [2].
Mitigation
As of the available references, Foxit Studio Photo is a legacy product and no specific patch for this CVE is mentioned. The Foxit security bulletin (reference [1]) primarily covers Foxit PDF Reader and Foxit PDF Editor; no update for Studio Photo is listed. Users should consider upgrading to a supported product if available, or avoid opening PSD files from untrusted sources. The ZDI advisory notes that Foxit was notified but no coordinated fix release is documented [2].
AI Insight generated on May 27, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
2- Range: =3.6.6.922
- Foxit/Studio Photov5Range: 3.6.6.922
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
2- www.foxitsoftware.com/support/security-bulletins.htmlmitrex_refsource_MISC
- www.zerodayinitiative.com/advisories/ZDI-20-1079/mitrex_refsource_MISC
News mentions
0No linked articles in our index yet.