Home / bulletins

MS08-046 – Critical: Vulnerability in Microsoft Windows Image Color Management System Could Allow Remote Code Execution (952954) - Version:1.0

Posted on 12 August 2008

Critical

Severity Rating: Critical - Revision Note: Bulletin published.Summary: This update resolves a privately reported vulnerability in the Microsoft Image Color Management (ICM) system that could allow remote code execution in the context of the current user. If a user is logged on with administrative user rights, an attacker who successfully exploited this vulnerability could take complete control of an affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights.

Link

 

TOP