E20-0xjy1
CVSS:
6.8 (AV:N/AC:M/Au:N/C:P/I:P/A:P)
False Positive:
t
Variants:
4
Year:
2020
Description
An out of bounds write vulnerability exists in Foxit Studio Photo 3.6.6.916, due to insufficient validation of a PSD file. The vulnerable parameter is 'ChannelID' field in a Layer Record structure, that gets parsed by the 'readChannelImageData' function, which may cause a integer underflow for certain values. By enticing an user to open a crafted document, a remote attacker may obtain code execution under the security context of the user.
CVE
Metasploit
http://www.zerodayinitiative.com/advisories/ZDI-20-301
Zdi
20-301