20080812 Microsoft Windows Color Management Module Heap Buffer Overflow VulnerabilityThird-party advisory
http://labs.idefense.com/intelligence/vulnerabilities/display.php?id=742 CVE-2008-2245
Microsoft Windows - InternalOpenColorProfile Heap Overflow (PoC) (MS08-046)
Record summary
CVE-2008-2245 has a selected CVSS score of 9.3; EIP currently links 1 catalogued exploit.
Description
Heap-based buffer overflow in the InternalOpenColorProfile function in mscms.dll in Microsoft Windows Image Color Management System (MSCMS) in the Image Color Management (ICM) component on Windows 2000 SP4, XP SP2 and SP3, and Server 2003 SP1 and SP2 allows remote attackers to execute arbitrary code via a crafted image file.
Description source: CVE List
Exploitation context
Available material
- Catalogued exploits
- 1
Proofs of concept
1Catalogued exploits
ExploitDBMicrosoft Windows - InternalOpenColorProfile Heap Overflow (PoC) (MS08-046)ExploitDB exploitby Ac!dDropNot analyzed1 file
References
12HPSBST02360Vendor advisory
http://marc.info/?l=bugtraq&m=121915960406986&w=2 31385Third-party advisory
http://secunia.com/advisories/31385 VU#309739Third-party advisory
http://www.kb.cert.org/vuls/id/309739 30594vdb entry
http://www.securityfocus.com/bid/30594 1020675vdb entry
http://www.securitytracker.com/id?1020675 TA08-225AThird-party advisory
http://www.us-cert.gov/cas/techalerts/TA08-225A.html ADV-2008-2350vdb entry
http://www.vupen.com/english/advisories/2008/2350 MS08-046Vendor advisory
https://docs.microsoft.com/en-us/security-updates/securitybulletins/2008/ms08-046 nvd.nist.gov
https://nvd.nist.gov/vuln/detail/CVE-2008-2245 oval:org.mitre.oval:def:5923vdb entrysignature
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A5923 6732exploit
https://www.exploit-db.com/exploits/6732