VYPR
Unrated severityNVD Advisory· Published Feb 9, 2021· Updated Aug 4, 2024

CVE-2020-17420

CVE-2020-17420

Description

This vulnerability allows remote attackers to disclose sensitive information on affected installations of Foxit Studio Photo 3.6.6.922. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of NEF files. The issue results from the lack of proper validation of user-supplied data, which can result in a read past the end of an allocated structure. An attacker can leverage this in conjunction with other vulnerabilities to execute code in the context of the current process. Was ZDI-CAN-11193.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Foxit Studio Photo 3.6.6.922 contains an out-of-bounds read vulnerability in NEF file parsing that could allow information disclosure if a user opens a malicious file.

Vulnerability

Foxit Studio Photo version 3.6.6.922 is affected by an out-of-bounds read vulnerability in the handling of NEF files. The issue stems from insufficient validation of user-supplied data, leading to a read past the end of an allocated structure [2].

Exploitation

Exploitation requires user interaction: the target must visit a malicious page or open a malicious NEF file. No additional privileges or network position are required beyond the user action [2].

Impact

Successful exploitation allows an attacker to disclose sensitive information from the process memory. An attacker can leverage this vulnerability in conjunction with other vulnerabilities to achieve code execution in the context of the current process [2].

Mitigation

No official fix has been publicly disclosed for this vulnerability as of the publication date (2021-02-09). Users should exercise caution when opening untrusted NEF files and monitor Foxit's security bulletins for future updates [1][2].

AI Insight generated on May 27, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

2

News mentions

0

No linked articles in our index yet.