CVE-2026-30040: Medium severity FastStone FastStone Image Viewer vulnerability
A heap overflow in the FSViewer.exe process of FastStone Image Viewer v8.3 allows attackers to cause a execute arbitrary code in the context of the current process via supplying a crafted JPEG 2000 (JP2) file.
Affected Software
Event History
Frequently Asked Questions
What does an attacker need to exploit this issue?
An attacker needs to supply a crafted JPEG 2000 (JP2) file to FastStone Image Viewer v8.3. No authentication or user interaction is identified in the provided CVSS vector.
What is the impact if exploitation succeeds?
Successful exploitation can execute arbitrary code in the context of the FSViewer.exe process. The reported CVSS impact includes low integrity and availability impact, with no confidentiality impact.
Which installations are known to be affected?
The affected product identified in the available data is FastStone Image Viewer v8.3. The provided information does not state whether other versions or default configurations are affected.