Faststone · Faststone Image Viewer · CVE-2026-30040
**Name of the Vulnerable Software and Affected Versions**
FastStone Image Viewer versions prior to 8.3.0.1
**Description**
Heap-based buffer overflow flaws exist in the JP2 and PSD file parsers within the FSViewer.exe process. A malformed QCD (quantization default) marker (0xFF5C) in a crafted JPEG 2000 (JP2) file can overwrite the EIP (instruction pointer), allowing for arbitrary code execution and control-flow corruption in the context of the current process. This issue can be triggered during directory enumeration, potentially without direct user interaction to open the file.
**Recommendations**
Avoid processing unknown or untrusted JP2 and PSD files.
At the moment, there is no information about a newer version that contains a fix for this vulnerability.