CVE-2018-0741

LOW

Description

The Color Management Module (Icm32.dll) in Windows 7 SP1 and Windows Server 2008 SP2 and R2 SP1 allows an information disclosure vulnerability due to the way objects are handled in memory, aka "Microsoft Color Management Information Disclosure Vulnerability".

References

http://www.securityfocus.com/bid/102349

http://www.securitytracker.com/id/1040093

https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2018-0741

Details

Source: MITRE

Published: 2018-01-04

Updated: 2018-01-18

Type: CWE-200

Risk Information

CVSS v2.0

Base Score: 2.6

Vector: AV:N/AC:H/Au:N/C:P/I:N/A:N

Impact Score: 2.9

Exploitability Score: 4.9

Severity: LOW

CVSS v3.0

Base Score: 5.3

Vector: CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N

Impact Score: 3.6

Exploitability Score: 1.6

Severity: MEDIUM