VYPR
Unrated severityNVD Advisory· Published Feb 9, 2021· Updated Aug 4, 2024

CVE-2020-17428

CVE-2020-17428

Description

This vulnerability allows remote attackers to disclose sensitive information on affected installations of Foxit Studio Photo 3.6.6.922. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of CMP files. The issue results from the lack of proper validation of user-supplied data, which can result in a read past the end of an allocated structure. An attacker can leverage this in conjunction with other vulnerabilities to execute code in the context of the current process. Was ZDI-CAN-11336.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

A crafted CMP file triggers an out-of-bounds read in Foxit Studio Photo 3.6.6.922, leaking memory contents via user interaction.

Vulnerability

This vulnerability affects Foxit Studio Photo version 3.6.6.922 and is rooted in the improper validation of user-supplied data when parsing CMP files. The specific flaw is an out-of-bounds read past the end of an allocated structure, occurring during the handling of CMP file content. An attacker can trigger this by convincing a user to open a malicious CMP file or visit a malicious page that loads such a file [1][2].

Exploitation

Exploitation requires user interaction: the target must open a crafted CMP file or navigate to a malicious web page that triggers file parsing. No special privileges or network position beyond the ability to deliver the file (e.g., via email, download, or web link) is needed. Upon opening the file, Foxit Studio Photo parses the CMP data without sufficient bounds checking, leading to a read that extends beyond the allocated memory region [2].

Impact

Successful exploitation allows an attacker to disclose sensitive information from the process memory of the current user. While the direct impact is limited to information disclosure, the advisory notes that an attacker can leverage this flaw in conjunction with other vulnerabilities to achieve arbitrary code execution in the context of the current process [1][2].

Mitigation

Foxit has not released a specific security bulletin for Studio Photo addressing this CVE. The referenced Foxit security bulletins page lists updates for Foxit PDF Reader and Foxit PDF Editor but does not mention a fix for Foxit Studio Photo [1]. Therefore, no official patch is publicly available. Users are advised to limit exposure by avoiding opening untrusted CMP files and applying general security best practices.

AI Insight generated on May 27, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

2

News mentions

0

No linked articles in our index yet.