vendor:
Windows Color Management Library
by:
Project Zero
7,8
CVSS
HIGH
Buffer Overflow
119
CWE
Product Name: Windows Color Management Library
Affected Version From: N/A
Affected Version To: N/A
Patch Exists: NO
Related CWE: N/A
CPE: N/A
Metasploit:
N/A
Other Scripts:
N/A
Tags: N/A
CVSS Metrics: N/A
Nuclei References:
N/A
Nuclei Metadata: N/A
Platforms Tested: Windows
2017
Crash in Windows Color Management Library
We have encountered a crash in the Windows Color Management library (icm32.dll), in the icm32!Fill_ushort_ELUTs_from_lut16Tag function, while trying to display a TIFF image with a malformed embedded color profile.
Mitigation:
Ensure that all TIFF images with embedded color profiles are valid and properly formatted.