VulnerabilityModified
CVE-2018-0741
The Color Management Module (Icm32.dll) in Windows 7 SP1 and Windows Server 2008 SP2 and R2 SP1 allows an information disclosure vulnerability due to the way objects are handled in memory, aka "Microsoft Color Management Information Disclosure…
MEDIUM 5.3EPSS 7.23%
Does this matter?
Lower severity and a low EPSS score (7.23%). Track it; it rarely justifies an emergency change on its own.
Description
The Color Management Module (Icm32.dll) in Windows 7 SP1 and Windows Server 2008 SP2 and R2 SP1 allows an information disclosure vulnerability due to the way objects are handled in memory, aka "Microsoft Color Management Information Disclosure Vulnerability".
- CVSS 3.0
- 5.3 MEDIUMCVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:N/A:N
- EPSS
- 7.23% probability · 94th percentile
- CISA KEV
- Not listed
- Affected
- microsoft/windows 7 · microsoft/windows server 2008
- Source
- secure@microsoft.com
References
- http://www.securityfocus.com/bid/102349Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1040093Third Party Advisory, VDB Entry
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2018-0741Patch, Vendor Advisory
- http://www.securityfocus.com/bid/102349Third Party Advisory, VDB Entry
- http://www.securitytracker.com/id/1040093Third Party Advisory, VDB Entry
- https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2018-0741Patch, Vendor Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.