ZDI-19-841: Foxit Studio Photo TIFF File Parsing Out-Of-Bounds Read Remote Code Execution Vulnerability
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Foxit Studio Photo. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the handling of TIFF files. The issue results from the lack of proper validation of user-supplied data, which can result in a read past the end of an allocated structure. An attacker can leverage this vulnerability to execute code in the context of the current process.
Affected Software
Event History
Frequently Asked Questions
Who is exposed to exploitation?
Users of affected Foxit Studio Photo installations are exposed when they visit a malicious page or open a malicious TIFF file. Exploitation runs code in the context of the current process.
What does an attacker need to exploit this issue?
An attacker needs to persuade the target to interact with attacker-controlled content, either by visiting a malicious page or opening a malicious file. No attacker privileges are required according to the supplied severity vector.
What file handling should be treated as risky?
TIFF file parsing is the affected functionality. Until remediation is available, avoid opening TIFF files from untrusted sources and avoid visiting untrusted pages that may deliver malicious content.