7.5
CVSSv2

CVE-2005-1219

Published: 12/07/2005 Updated: 12/10/2018
CVSS v2 Base Score: 7.5 | Impact Score: 6.4 | Exploitability Score: 10
VMScore: 760
Vector: AV:N/AC:L/Au:N/C:P/I:P/A:P

Vulnerability Summary

Buffer overflow in the Microsoft Color Management Module for Windows allows remote malicious users to execute arbitrary code via an image with crafted ICC profile format tags.

Vulnerable Product Search on Vulmon Subscribe to Product

microsoft image color management

Exploits

/* * Author: snooq [wwwredpuffernet/snooq/web/] * Date: 21 July 2005 * * When I looked at the PoC posted on bugtraq * I was basically quite disappointed The 'PoC' fixed * 'tag count' to a large number but this code path * does not seem to be exploitable GetColorProfileElement * crashes becoz it hits the page boundary while enum ...
/* \ MS05-036 ICC Stack Overflow Exploit / by Darkeagle \ / GreetZ: all unl0ckerz, ed, f0st, uf0, sowhat, str0ke, #black, redsand \ / \ special tnx to snooq for his PoC / \ / xploit was tested on WinXP SP1 RUS with explorerexe \ / 020805 \ / eagleblacksecurityorg \ */ #include <stringh> #include <stdioh> #incl ...