VYPR
Unrated severityNVD Advisory· Published Mar 20, 2020· Updated Aug 4, 2024

CVE-2020-8882

CVE-2020-8882

Description

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit Studio Photo 3.6.6.916. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of the PSD files. The issue results from the lack of proper initialization of a pointer prior to accessing it. An attacker can leverage this vulnerability to execute code in the context of the current process. Was ZDI-CAN-9811.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Foxit Studio Photo 3.6.6.916 contains an uninitialized pointer vulnerability in PSD file parsing, allowing remote code execution with user interaction.

Vulnerability

This vulnerability exists in Foxit Studio Photo version 3.6.6.916. The flaw resides in the handling of PSD files; the issue results from the lack of proper initialization of a pointer before it is accessed. The vulnerability is reachable when the target user visits a malicious webpage or opens a malicious PSD file. Affected versions are Foxit Studio Photo 3.6.6.916 [1][2].

Exploitation

To exploit this vulnerability, an attacker must convince the target user to open a specially crafted PSD file or visit a malicious page that triggers the parsing of such a file. No other special network position or authentication is required beyond the user interaction. The attacker constructs a PSD file that causes the code to access an uninitialized pointer, leading to arbitrary code execution [1][2].

Impact

Successful exploitation allows the attacker to execute arbitrary code in the context of the current user process. This can result in full compromise of the affected system: disclosure of sensitive information, modification of data, or denial of service. The CVSS v3.0 score is 7.8 (High) with vector AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H, indicating high impact on confidentiality, integrity, and availability [1][2].

Mitigation

Foxit has released security updates for related products, but the available references do not explicitly state a fixed version for Foxit Studio Photo 3.6.6.916. Users should check Foxit's security bulletins for updated versions. As of now, no specific patch is confirmed for this CVE in the provided references. It is recommended to use caution when opening PSD files from untrusted sources [1][2].

AI Insight generated on May 27, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

2

News mentions

0

No linked articles in our index yet.