VYPR
Unrated severityNVD Advisory· Published Feb 9, 2021· Updated Aug 4, 2024

CVE-2020-17419

CVE-2020-17419

Description

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit Studio Photo 3.6.6.922. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of NEF files. The issue results from the lack of proper validation of user-supplied data, which can result in a write past the end of an allocated structure. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-11192.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Foxit Studio Photo 3.6.6.922 has an out-of-bounds write in NEF file parsing, allowing remote code execution via a malicious NEF file.

Vulnerability

The vulnerability resides in Foxit Studio Photo version 3.6.6.922 during the processing of NEF files. A lack of proper validation of user-supplied data results in a write past the end of an allocated structure, allowing memory corruption [2].

Exploitation

To exploit, an attacker must craft a malicious NEF file and convince the target user to open it, either by direct file opening or via a malicious webpage that triggers the parsing. No additional privileges are required beyond user interaction [2].

Impact

Successful exploitation enables arbitrary code execution in the context of the Foxit Studio Photo process, potentially leading to full system compromise with high impact on confidentiality, integrity, and availability (CVSS 7.8) [2].

Mitigation

As of the advisory publication date, Foxit has not released a specific security update for this vulnerability. Users are advised to exercise caution when opening NEF files from untrusted sources and to monitor Foxit's security bulletins for any future patches [1].

AI Insight generated on May 27, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

2

News mentions

0

No linked articles in our index yet.