CVE-2017-0063
The Color Management Module (ICM32.dll) memory handling functionality in Windows Vista SP2; Windows Server 2008 SP2 and
The Color Management Module (ICM32.dll) memory handling functionality in Windows Vista SP2.
Windows Server 2008 SP2 and R2.
and Windows 7 SP1.
Windows 8.1.
Windows Server 2012 Gold and R2.
Windows RT 8.1.
Windows 10 Gold, 1511, and 1607.
and Windows Server 2016 allows remote attackers to bypass ASLR and execute code in combination with another vulnerability through a crafted website, aka "Microsoft Color Management Information Disclosure Vulnerability." This vulnerability is different from that described in CVE-2017-0061.
MEDIUM · CVSS 6.5
EPSS 0.16295
Schedule remediation
- EPSS ≥ 0.10 - elevated exploitation probability
- EPSS percentile: top 5% of all CVEs by exploitation likelihood
- Public exploit or PoC is available
Sigma rules0
YARA rules0