CERT-In Vulnerability Note
CIVN-2005-0064
Vulnerability in Microsoft Color Management Module Could Allow Remote Code Execution
Original Issue Date:July 13, 2005
Severity Rating: HIGH
Software Affected
Microsoft Windows 98 Microsoft Windows 98 Second Edition Microsoft Windows Millennium Microsoft Windows 2000 Advanced Server Microsoft Windows 2000 Datacenter Server Microsoft Windows 2000 Professional Microsoft Windows 2000 Server Microsoft Windows XP Home Edition Microsoft Windows XP Professional Microsoft Windows Server 2003 Datacenter Edition Microsoft Windows Server 2003 Enterprise Edition Microsoft Windows Server 2003 Standard Edition Microsoft Windows Server 2003 Web Edition
Overview
A vulnerability has been reported in Microsoft color management module which could be exploited by an attacker by creating a maliciously crafted image file and enticing a user to view the same locally or by previewing an e-mail message containing the malicious image, or by opening an e-mail attachment that contains a malicious image.
Description
The Microsoft Color Management Module allows the operating system to provide consistent color mappings between different devices and applications. The vulnerability is caused due to a boundary error when validating ICC profile format tags.
When the malicious image file is processed by the target user, it will trigger a buffer overflow enabling the attacker to execute arbitrary code on the target users system. The code will run with the privileges of the target user.
Solution
Apply the appropriate patches as mentioned in Microsoft Security Bulletin
MS05-036
Vendor Information
Microsoft
http://www.microsoft.com/technet/security/bulletin/MS05-036.mspx
References
Secunia Advisory
http://secunia.com/advisories/16004/
CVE Name
CAN-2005-1219
Disclaimer
The information provided herein is on "as is" basis, without warranty of any kind.
Contact Information
Email: info@cert-in.org.in Phone: +91-11-2436857
Postal address
Indian Computer Emergency Response Team (CERT-In) Ministry of Electronics and Information Technology Government of India Electronics Niketan 6, CGO Complex, Lodhi Road, New Delhi - 110 003 India
|