VYPR
Unrated severityNVD Advisory· Published Feb 9, 2021· Updated Aug 4, 2024

CVE-2020-17422

CVE-2020-17422

Description

This vulnerability allows remote attackers to disclose sensitive information on affected installations of Foxit Studio Photo 3.6.6.922. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of EPS files. The issue results from the lack of proper validation of user-supplied data, which can result in a read past the end of an allocated structure. An attacker can leverage this in conjunction with other vulnerabilities to execute code in the context of the current process. Was ZDI-CAN-11195.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Foxit Studio Photo 3.6.6.922 has a out-of-bounds read in EPS parsing, enabling information disclosure via a malicious file.

Vulnerability

Foxit Studio Photo version 3.6.6.922 is affected by an out-of-bounds read vulnerability in the handling of EPS files. The flaw exists due to a lack of proper validation of user-supplied data, which can result in a read past the end of an allocated structure. The vulnerability is identified as CVE-2020-17422 (ZDI-CAN-11195) and requires user interaction to be triggered [1][2].

Exploitation

An attacker can exploit this vulnerability by convincing a target to visit a malicious page or open a specially crafted EPS file. No special privileges or authentication are required; user interaction is the only prerequisite. The specific sequence involves the EPS parser reading beyond the bounds of an allocated structure when processing the malicious file [2].

Impact

Successful exploitation allows an attacker to disclose sensitive information from the memory space of the affected process. While the vulnerability itself only leaks information, an attacker can potentially leverage this in conjunction with other vulnerabilities to execute arbitrary code in the context of the current process [2].

Mitigation

As of the publication date, no specific fix for CVE-2020-17422 has been confirmed in available references. Users should exercise caution when opening EPS files from untrusted sources. The vendor's security bulletins page [1] lists updates for other Foxit products but does not mention a patch for Studio Photo. Users are advised to monitor the vendor's website for updates.

AI Insight generated on May 27, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

2

News mentions

0

No linked articles in our index yet.