Microsoft Windows Color Management Module ICC Profile Buffer Overflow Vulnerability

Microsoft has stated that they have received reports that this vulnerability has been exploited in the wild.

Exploit code (ms_icc_exp.c) has been provided by snooq.

UPDATE: Core Security Technologies has developed a working commercial exploit for its CORE IMPACT product. This exploit is not otherwise publicly available or known to be circulating in the wild.


 

Privacy Statement
Copyright 2010, SecurityFocus