VU#936962: Multiple file parsing vulnerabilities in FastStone Image Viewer 8.3.0.0
2026-06-23T20:52:16Z•bf7cd56224fa09d93cdd80ad0c0098bec24f9e945ffbbb834f05b20a379ce0b2
BYOVDCVE-2026-9648DACLDBXHaskell TLSIOCTLNameConstraintsSecure Boot bypassSecurlyUEFIauto-thumbnail parsingbrowser extensioncertificate validationdenial of servicefirmware password bypasshardcoded keysheap overflowimage parserinteger overflowkernel driverprivilege escalationremote code executionshimsupply chainweak cryptography
What happened
Collection of CERT/CC vulnerability notes covering multiple high-impact issues: FastStone Image Viewer 8.3 and earlier contains two image-parsing flaws (CVE-2026-30040: critical JP2 heap overflow enabling remote code execution via automatic thumbnail parsing; CVE-2026-30041: PSD integer overflow). UEFI/firmware concerns include WinRE-related paths that can bypass UEFI/BIOS password enforcement, multiple vendor-signed UEFI applications vulnerable to Secure Boot bypass via BYOVD techniques, and Microsoft-signed shim bootloaders subject to Secure Boot bypass mitigations (DBX updates recommended).
Why it matters
A reviewed impact interpretation has not been published for this record.
Evidence and limitations
- Source ID
- certcc_vulnotes
- Record identifier
- bf7cd56224fa09d93cdd80ad0c0098bec24f9e945ffbbb834f05b20a379ce0b2
- Enrichment time
- 2026-06-23T20:52:16Z
- AI-assisted enrichment
- Yes
This record may overlap with other records. Its enrichment can be incomplete or wrong, and machine assistance was used. Validate consequential decisions against the linked source and your own environment.