Vulnerability record · CVE-2005-1219 · published 12 July 2005
CVE-2005-1219: Microsoft Color Management Module buffer overflow via crafted ICC profile tags
Microsoft · Image Color Management
The Microsoft Color Management Module for Windows contains a buffer overflow that is triggered when processing an image with crafted ICC profile format tags. Because the flaw is reachable through image parsing, it matters to any Windows system that renders untrusted images, and successful exploitation can lead to arbitrary code execution.
Description
Buffer overflow in the Microsoft Color Management Module for Windows allows remote attackers to execute arbitrary code via an image with crafted ICC profile format tags.
AV:N/AC:L/Au:N/C:P/I:P/A:P
Automated analysis
high priorityThe flaw is remotely reachable without authentication and can lead to code execution, and EPSS indicates a high likelihood of exploitation activity despite no KEV listing.
What it is
The Microsoft Color Management Module for Windows contains a buffer overflow that is triggered when processing an image with crafted ICC profile format tags. Because the flaw is reachable through image parsing, it matters to any Windows system that renders untrusted images, and successful exploitation can lead to arbitrary code execution.
Impact
An attacker can execute arbitrary code in the context of the process that parses the image, which may be the logged-on user or a service. This can lead to full compromise of the affected system.
Attack surface
The vulnerability is network-reachable (AV:N) with low complexity and no authentication (AC:L/Au:N), so it can be reached by delivering a crafted image to a vulnerable application or service. User interaction is not required by the vector, though in practice the image must be processed by the target.
Exploitation
CVE-2005-1219 is not listed in CISA KEV, but EPSS shows a 30-day probability of 0.49922 (98.8th percentile), indicating high predicted exploitation activity. References include vendor patch and US Government advisories, but no public exploit tags are present in the record.
What to do
- Apply the Microsoft security update for MS05-036 (or the current supported patch level) to all affected Windows systems.
- Block or restrict processing of untrusted ICC profile images at email gateways, web proxies, and file upload endpoints.
- Disable or restrict unnecessary image rendering services and applications that use the Color Management Module.
- Enforce least privilege so that image-processing processes run with minimal rights, limiting the impact of code execution.
- Monitor vendor advisories and replace end-of-life Windows versions that no longer receive security updates.
Detection
- Hunt for image files containing malformed or unusually large ICC profile tags, especially those delivered via email or web downloads.
- Monitor for crashes or abnormal terminations in processes that load the Color Management Module (e.g., imaging, printing, or document viewers).
- Use endpoint detection to flag unexpected child processes or code execution originating from image-rendering applications.
- Review application and system logs for repeated image parsing failures that could indicate exploitation attempts.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2005-1219 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Source: NIST National Vulnerability Database (record CVE-2005-1219), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.