Skip to content
Critical Out-of-Bounds Write Vulnerability in FastStone Image Viewer

Critical Out-of-Bounds Write Vulnerability in FastStone Image Viewer

First seen 29 Sep 2026, 13:10 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •September 29, 2026 at 13:11 UTC
  • •CVE-2026-101203 affects FastStone Image Viewer versions up to 8.3.
  • •The vulnerability allows remote attackers to exploit an out-of-bounds write condition.
  • •User interaction is required to trigger the vulnerability by opening crafted image files.

A vulnerability, CVE-2026-101203, has been identified in FastStone Image Viewer versions up to 8.3, specifically in the 1bpp RLE Decoder component. This out-of-bounds write vulnerability allows remote attackers to manipulate the application by sending specially crafted image files that require user interaction to open. The attack can lead to memory corruption, potentially compromising the application's integrity and availability. The vendor has been contacted but has not responded to the disclosure. The vulnerability was published on September 28, 2026, and is rated with a CVSS score of 6.3, indicating a high risk if left unpatched. Organizations are advised to avoid opening untrusted image files and to update the application once a patch is available. Currently, there is no evidence of public proof-of-concept exploitation. The attack complexity is low, and no privileges are required for exploitation.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated just now How this analysis works

Timeline

2026-09-28
CVE-2026-101203 published
Vulnerability disclosed affecting FastStone Image Viewer up to version 8.3, allowing remote exploitation.
cve.akaoma.com
2026-09-28
Vulnerability reported to vendor
The vendor was contacted regarding the vulnerability but has not responded.
cve.threatint.com
2026-09-29
Current status update
No patch information is available; organizations are advised to avoid untrusted image files.
Feedly
2026-09-29
CVE-2026-96423 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE

More articles in this cluster (5)

Following this threat?

Track CVE-2026-101203 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed