Skip to content

Latest commit

 

History

History
31 lines (21 loc) · 980 Bytes

FEYE-2020-0005.md

File metadata and controls

31 lines (21 loc) · 980 Bytes

FEYE-2020-0005

Description

A remote code execution vulnerability exists in the way that the Color Management Module (ICM32.dll) handles objects in memory. A crafted Named Color Profile can lead to out of bound write to a heap memory due to a faulty bounds check.

Impact

High - Remote Code Execution

Exploitability

High - Color Profiles widely accessible through containers like images

CVE Reference

CVE-2020-1117

Technical Details

A crafted Named Color Profile can lead to an out of bound write while performing color transformation.

Resolution

This issue was fixed as part of May 2020 patch by fixing the faulty bounds check

Discovery Credits

Dhanesh Kizhakkinan

Disclosure Timeline

  • 04 February 2020 - Issue reported to vendor
  • 18 February 2020 - Issue confirmed
  • 12 May 2020 - Issue fixed and security advisory released

References

Microsoft Advisory