CVE-2020-8882
Description
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit Studio Photo 3.6.6.916. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of the PSD files. The issue results from the lack of proper initialization of a pointer prior to accessing it. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-9811.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Foxit Studio Photo 3.6.6.916 contains an uninitialized pointer vulnerability in PSD file parsing, allowing remote code execution with user interaction.
Vulnerability
This vulnerability exists in Foxit Studio Photo version 3.6.6.916. The flaw resides in the handling of PSD files; the issue results from the lack of proper initialization of a pointer before it is accessed. The vulnerability is reachable when the target user visits a malicious webpage or opens a malicious PSD file. Affected versions are Foxit Studio Photo 3.6.6.916 [1][2].
Exploitation
To exploit this vulnerability, an attacker must convince the target user to open a specially crafted PSD file or visit a malicious page that triggers the parsing of such a file. No other special network position or authentication is required beyond the user interaction. The attacker constructs a PSD file that causes the code to access an uninitialized pointer, leading to arbitrary code execution [1][2].
Impact
Successful exploitation allows the attacker to execute arbitrary code in the context of the current user process. This can result in full compromise of the affected system: disclosure of sensitive information, modification of data, or denial of service. The CVSS v3.0 score is 7.8 (High) with vector AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H, indicating high impact on confidentiality, integrity, and availability [1][2].
Mitigation
Foxit has released security updates for related products, but the available references do not explicitly state a fixed version for Foxit Studio Photo 3.6.6.916. Users should check Foxit's security bulletins for updated versions. As of now, no specific patch is confirmed for this CVE in the provided references. It is recommended to use caution when opening PSD files from untrusted sources [1][2].
AI Insight generated on May 27, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
2- Range: =3.6.6.916
- Foxit/Studio Photov5Range: 3.6.6.916
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
2- www.foxitsoftware.com/support/security-bulletins.phpmitrex_refsource_MISC
- www.zerodayinitiative.com/advisories/ZDI-20-305/mitrex_refsource_MISC
News mentions
0No linked articles in our index yet.