CVE-2020-17425
Description
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit Studio Photo 3.6.6.922. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of EPS files. The issue results from the lack of proper validation of user-supplied data, which can result in a write past the end of an allocated structure. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-11259.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Foxit Studio Photo 3.6.6.922 has a heap buffer overflow in EPS parsing, allowing remote code execution.
Vulnerability
Foxit Studio Photo version 3.6.6.922 is vulnerable to a heap-based out-of-bounds write during the parsing of EPS files. The flaw is caused by a lack of proper validation of user-supplied data within the EPS parsing routine, leading to a write past the end of an allocated structure. Affected version: Foxit Studio Photo 3.6.6.922 [1][2].
Exploitation
Exploitation requires user interaction; the target must visit a malicious web page or open a malicious EPS file. An attacker can craft a specially crafted EPS file that triggers the out-of-bounds write when parsed by the vulnerable application. No authentication or special privileges are needed, as the vulnerability is accessible over the network via a remote attack vector [2].
Impact
Successful exploitation allows an attacker to execute arbitrary code in the context of the current process. This can lead to full compromise of confidentiality, integrity, and availability of the affected system, as the attacker can run arbitrary commands with the privileges of the Foxit Studio Photo process [2].
Mitigation
As of the available references, a fixed version of Foxit Studio Photo has not been explicitly disclosed for this CVE. Foxit’s security bulletins primarily cover Foxit PDF Reader and Foxit PDF Editor, not Studio Photo. Users should monitor Foxit’s advisory page or consider isolating the application until an official patch is released [1].
AI Insight generated on May 27, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
2- Range: = 3.6.6.922
- Foxit/Studio Photov5Range: 3.6.6.922
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
2- www.foxitsoftware.com/support/security-bulletins.htmlmitrex_refsource_MISC
- www.zerodayinitiative.com/advisories/ZDI-20-1336/mitrex_refsource_MISC
News mentions
0No linked articles in our index yet.