ZDI-26-543: Microsoft Windows ICC File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability
ZDI discloses an out-of-bounds write in Windows ICC file parsing via Mscms.dll enabling remote code execution (CVE-2026-54984, CVSS 7.8).
ZDI advisory ZDI-26-543 describes an out-of-bounds write in Microsoft Windows ICC file parsing that allows remote attackers to execute arbitrary code. Exploitation requires interaction with the Mscms.dll color management library, though attack vectors may vary by implementation. The flaw has a CVSS rating of 7.8 and is assigned CVE-2026-54984.
- Out-of-bounds write in Windows ICC color profile file parsing
- Remote code execution via interaction with Mscms.dll
- CVSS 7.8, assigned CVE-2026-54984
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-54984 | Heap Buffer Overflow in Microsoft Windows Imaging Component (ICC Parsing) CVE-2026-54984 is a heap-based buffer overflow (CWE-122) in the Windows Imaging Component, the core imaging and color-management engine built into Windows. Related advisory coverage (ZDI-26-543) ties the flaw to an out-of-bounds write while parsing ICC color-profile data embedded in image files, meaning a crafted image containing a malicious ICC profile triggers the bug when a user opens, previews, or otherwise processes it. Because the CVSS vector is AV:L with UI:R, exploitation requires user interaction rather than a network-facing service; a successful attacker executes code with the privileges of the local user, with high impact to confidentiality, integrity, and availability. Nearly every supported Windows deployment is affected, since the listed versions span Windows 10 (1607 through 22H2), Windows 11 (23H2 through 26H1), and Windows Server 2012 through 2022. There is no known public proof of concept, the flaw is not in CISA's KEV, and EPSS puts 30-day exploitation odds at about 0.6%, so no in-the-wild exploitation is known at this time. Do: Apply Microsoft's security update for CVE-2026-54984 across all affected Windows 10, Windows 11, and Windows Server systems, prioritizing machines and servers that process untrusted images (email attachments, browser downloads, shared folders, thumbnail/print pipelines); older Windows 10 releases and Windows Server 2012 may only receive the fix via extended support channels such as ESU. Until patched, instruct users not to open image files from untrusted sources and review any automated processing of untrusted images with ICC profiles attached. Verify remediation by confirming the relevant Microsoft security update is installed on each affected release rather than relying on a single KB across all versions. | 7.8 | <1% |
| masshundreds of millions of unpatched Windows 10/11 client and Windows Server installations |
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Microsoft Windows. Interaction with the Mscms.dll color management library is required to exploit this vulnerability but attack vectors may vary depending on the implementation. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2026-54984.
This source does not provide full text. Read it at zerodayinitiative.com.