Use-after-free in Foxit Studio Photo - CVE-2020-8881

 

Use-after-free in Foxit Studio Photo - CVE-2020-8881

Published: March 17, 2020 / Updated: March 19, 2020


Vulnerability identifier: #VU26122
CSH Severity: High
CVSS v4 BT: 5.7 [CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Amber]
CVE-ID: CVE-2020-8881
CWE-ID: CWE-416
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to compromise vulnerable system.

The vulnerability exists due to a use-after-free error when processing TIFF files. A remote attacker can trick a victim to open a specially crafted TIFF file or visit a malicious page and execute arbitrary code on the target system.

Successful exploitation of the vulnerability may allow an attacker to compromise vulnerable system.


Affected software

Foxit Studio Photo

How to mitigate CVE-2020-8881

Install updates from vendor's website.

Foxit Studio Photo - update to 3.6.6.922

External References

Related Security Bulletins