Remote Code Execution in Microsoft Color Management Module
The Microsoft Color Management Module contains a flaw in the way it processes International Color Code (ICC) profile format tags.
July 12, 2005
ReportedJuly 12, 2005 by Microsoft
VERSIONS AFFECTED
Windows 98Windows 2000Windows XPWindows Server 2003 |
DESCRIPTION
The JView Profilercontains a flaw in the way it processes International Color Code (ICC)profile format tags. The flaw could allow a remote intruder to takecompletecontrol of an affected system.
VENDOR RESPONSE
Microsoft released asecurity bulletin, "Vulnerabilityin Microsoft Color Management Module Could Allow Remote Code Execution(901214)," andan associatedpatch to correct the problem.
CREDIT
Discovered by Shih-haoWeng of Information & Communication Security Technology Center(ICST)
Read more about:
MicrosoftAbout the Author
You May Also Like