VYPR
Unrated severityNVD Advisory· Published Feb 9, 2021· Updated Aug 4, 2024

CVE-2020-17434

CVE-2020-17434

Description

This vulnerability allows remote attackers to disclose sensitive information on affected installations of Foxit Studio Photo 3.6.6.922. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the parsing of ARW files. The issue results from the lack of proper validation of user-supplied data, which can result in a read past the end of an allocated structure. An attacker can leverage this in conjunction with other vulnerabilities to execute code in the context of the current process. Was ZDI-CAN-11357.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Foxit Studio Photo 3.6.6.922 has an out-of-bounds read in ARW parsing, allowing info disclosure via a malicious file.

Vulnerability

This vulnerability affects Foxit Studio Photo version 3.6.6.922. The flaw resides in the parsing of ARW (Sony Raw) files. Due to improper validation of user-supplied data, the parser performs a read past the end of an allocated structure, leading to an out-of-bounds read condition [1][2].

Exploitation

The attacker must convince the target to visit a malicious page or open a crafted ARW file. No authentication or special privileges are required beyond user interaction. No additional privileges or race conditions are needed; the vulnerability is triggered during normal file processing [2].

Impact

A successful exploit allows an attacker to disclose sensitive information from process memory. This information disclosure (confidentiality impact) can be leveraged in conjunction with other vulnerabilities to achieve code execution in the context of the current process [2]. The CVSS score is 3.3 (low severity) [2].

Mitigation

As of the available references, no fix has been released for Foxit Studio Photo 3.6.6.922. The vendor's security bulletin does not mention this product [1]. Users should exercise caution when opening ARW files from untrusted sources. No workaround is provided.

AI Insight generated on May 27, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

2

News mentions

0

No linked articles in our index yet.