ZDI-26-543: Microsoft Windows ICC File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Microsoft Windows. Interaction with the Mscms.dll color management library is required to exploit this vulnerability but attack vectors may vary depending on the implementation. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-54984.
Affected Software
Event History
Frequently Asked Questions
What is the severity of ZDI-26-543?
The severity of ZDI-26-543 is rated at 77.
How do I fix ZDI-26-543?
To fix ZDI-26-543, apply the latest security updates from Microsoft for affected versions of Windows.
What type of attacks can be executed using ZDI-26-543?
ZDI-26-543 allows remote attackers to execute arbitrary code on vulnerable installations of Microsoft Windows.
Which library is involved in the exploitation of ZDI-26-543?
The exploitation of ZDI-26-543 involves interaction with the Mscms.dll color management library.
Is user interaction required to exploit ZDI-26-543?
While direct user interaction may not be required, exploitation of ZDI-26-543 will typically depend on the implementation involved.