Junglewise Threat Intelligence

CVE-2026-30040: FastStone Image Viewer heap overflow in JP2 parser

CVE-2026-30040 · Severity: info · CVSS 8.8 · Published 2026-06-26

Executive brief

FastStone Image Viewer is a popular application used for browsing and managing digital photos. A security flaw allows attackers to take control of a user's computer if the application processes a specially crafted image file. This can happen automatically if the malicious file is simply saved in a folder the user is browsing, potentially leading to data theft or malware installation.

Technical details

A heap-based buffer overflow exists in the FSViewer.exe process of FastStone Image Viewer (v8.3 and earlier) during the parsing of JPEG 2000 (JP2) files. The vulnerability is triggered by a malformed QCD (quantization default, 0xFF5C) marker. An attacker can exploit this by providing a crafted JP2 file; notably, the vulnerability can be triggered automatically during directory enumeration for thumbnail generation if the file is within two directory levels of the current view. Successful exploitation allows an attacker to overwrite the instruction pointer (EIP) and execute arbitrary code in the context of the current process. While the vendor has released version 8.5, the advisory notes that coordination was unsuccessful, though users are encouraged to update to the latest version.

Affected products

  • FastStone Image Viewer 8.3 and earlier

Timeline

  • 2026-05-12: other: Vendor notified
  • 2026-06-22: disclosed: Initial disclosure by CERT/CC
  • 2026-06-24: patched: Version 8.5 released (assumed fix based on release date)
  • 2026-06-26: advisory: NVD publication

References

Related threats