← Vulnerability feed

Vulnerability record · CVE-2005-1219 · published 12 July 2005

CVE-2005-1219: Microsoft Color Management Module buffer overflow via crafted ICC profile tags

Microsoft · Image Color Management

The Microsoft Color Management Module for Windows contains a buffer overflow that is triggered when processing an image with crafted ICC profile format tags. Because the flaw is reachable through image parsing, it matters to any Windows system that renders untrusted images, and successful exploitation can lead to arbitrary code execution.

7.5 CVSS 2.0 High EPSS 50% · top 1.1%
7.5CVSS 2.0 base score
50%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
20References
16 Jun 2026Last modified by NVD

Description

Buffer overflow in the Microsoft Color Management Module for Windows allows remote attackers to execute arbitrary code via an image with crafted ICC profile format tags.

AV:N/AC:L/Au:N/C:P/I:P/A:P

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 20 September 2026. Confidence: medium.

high priorityThe flaw is remotely reachable without authentication and can lead to code execution, and EPSS indicates a high likelihood of exploitation activity despite no KEV listing.

What it is

The Microsoft Color Management Module for Windows contains a buffer overflow that is triggered when processing an image with crafted ICC profile format tags. Because the flaw is reachable through image parsing, it matters to any Windows system that renders untrusted images, and successful exploitation can lead to arbitrary code execution.

Impact

An attacker can execute arbitrary code in the context of the process that parses the image, which may be the logged-on user or a service. This can lead to full compromise of the affected system.

Attack surface

The vulnerability is network-reachable (AV:N) with low complexity and no authentication (AC:L/Au:N), so it can be reached by delivering a crafted image to a vulnerable application or service. User interaction is not required by the vector, though in practice the image must be processed by the target.

Exploitation

CVE-2005-1219 is not listed in CISA KEV, but EPSS shows a 30-day probability of 0.49922 (98.8th percentile), indicating high predicted exploitation activity. References include vendor patch and US Government advisories, but no public exploit tags are present in the record.

What to do

  • Apply the Microsoft security update for MS05-036 (or the current supported patch level) to all affected Windows systems.
  • Block or restrict processing of untrusted ICC profile images at email gateways, web proxies, and file upload endpoints.
  • Disable or restrict unnecessary image rendering services and applications that use the Color Management Module.
  • Enforce least privilege so that image-processing processes run with minimal rights, limiting the impact of code execution.
  • Monitor vendor advisories and replace end-of-life Windows versions that no longer receive security updates.

Detection

  • Hunt for image files containing malformed or unusually large ICC profile tags, especially those delivered via email or web downloads.
  • Monitor for crashes or abnormal terminations in processes that load the Color Management Module (e.g., imaging, printing, or document viewers).
  • Use endpoint detection to flag unexpected child processes or code execution originating from image-rendering applications.
  • Review application and system logs for repeated image parsing failures that could indicate exploitation attempts.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
http://secunia.com/advisories/16004/ PatchVendor Advisory
http://www.kb.cert.org/vuls/id/720742 US Government Resource
http://www.securityfocus.com/bid/14214
http://www.us-cert.gov/cas/techalerts/TA05-193A.html US Government Resource
https://docs.microsoft.com/en-us/security-updates/securitybulletins/2005/ms05-036
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1125
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1280
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A330
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A440
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A769
http://secunia.com/advisories/16004/ PatchVendor Advisory
http://www.kb.cert.org/vuls/id/720742 US Government Resource
http://www.securityfocus.com/bid/14214
http://www.us-cert.gov/cas/techalerts/TA05-193A.html US Government Resource
https://docs.microsoft.com/en-us/security-updates/securitybulletins/2005/ms05-036
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1125
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A1280
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A330
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A440
https://oval.cisecurity.org/repository/search/definition/oval%3Aorg.mitre.oval%3Adef%3A769

Track CVE-2005-1219 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Source: NIST National Vulnerability Database (record CVE-2005-1219), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.