Remote Code Execution in Microsoft Color Management Module

The Microsoft Color Management Module contains a flaw in the way it processes International Color Code (ICC) profile format tags.

ITPro Today

July 12, 2005

1 Min Read
ITPro Today logo

ReportedJuly 12, 2005 by Microsoft

VERSIONS AFFECTED

Windows 98Windows 2000Windows XPWindows Server 2003

DESCRIPTION

The JView Profilercontains a flaw in the way it processes International Color Code (ICC)profile format tags. The flaw could allow a remote intruder to takecompletecontrol of an affected system.

VENDOR RESPONSE

Microsoft released asecurity bulletin, "Vulnerabilityin Microsoft Color Management Module Could Allow Remote Code Execution(901214)," andan associatedpatch to correct the problem.

CREDIT

Discovered by Shih-haoWeng of Information & Communication Security Technology Center(ICST)

Read more about:

Microsoft
Sign up for the ITPro Today newsletter
Stay on top of the IT universe with commentary, news analysis, how-to's, and tips delivered to your inbox daily.

You May Also Like