Vulnerability record · CVE-2008-2245 · published 13 August 2008
CVE-2008-2245: Microsoft Windows Image Color Management heap buffer overflow via crafted image
Microsoft · Windows 2000
The InternalOpenColorProfile function in mscms.dll, part of the Windows Image Color Management (ICM) component, contains a heap-based buffer overflow (CWE-119). A remote attacker can trigger it with a crafted image file, and successful exploitation allows arbitrary code execution in the context of the affected process. The flaw affects Windows 2000 SP4, XP SP2/SP3, and Server 2003 SP1/SP2.
Description
Heap-based buffer overflow in the InternalOpenColorProfile function in mscms.dll in Microsoft Windows Image Color Management System (MSCMS) in the Image Color Management (ICM) component on Windows 2000 SP4, XP SP2 and SP3, and Server 2003 SP1 and SP2 allows remote attackers to execute arbitrary code via a crafted image file.
AV:N/AC:M/Au:N/C:C/I:C/A:C
Automated analysis
high priorityCVSS 9.3, public exploit code, and a very high EPSS score make this a serious risk for any remaining unpatched legacy Windows systems.
What it is
The InternalOpenColorProfile function in mscms.dll, part of the Windows Image Color Management (ICM) component, contains a heap-based buffer overflow (CWE-119). A remote attacker can trigger it with a crafted image file, and successful exploitation allows arbitrary code execution in the context of the affected process. The flaw affects Windows 2000 SP4, XP SP2/SP3, and Server 2003 SP1/SP2.
Impact
An attacker who gets a crafted image processed gains arbitrary code execution with the privileges of the user or service handling the image. That can lead to full system compromise depending on the process context.
Attack surface
The vector is network-reachable (AV:N) with no authentication required (Au:N), but exploitation requires medium complexity (AC:M) and depends on the victim opening or processing a malicious image file. User interaction is implied by the crafted-image delivery model, though the record does not state it explicitly.
Exploitation
CISA KEV does not list this CVE, but EPSS is high at 0.46142 (98.756th percentile), and a public Exploit-DB entry (6732) exists, indicating exploit code is publicly available.
What to do
- Apply Microsoft security bulletin MS08-046 for the affected Windows versions.
- Upgrade or retire Windows 2000, XP, and Server 2003 systems that cannot be patched.
- Block or filter untrusted image files at email and web gateways where feasible.
- Restrict user privileges so image-processing processes run with least privilege.
Detection
- Monitor for crashes or abnormal terminations in processes loading mscms.dll.
- Hunt for image files opened from untrusted sources that trigger mscms.dll activity outside normal workflows.
- Use the OVAL definition (oval:org.mitre.oval:def:5923) to check patch state on affected hosts.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
3 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2008-2245 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2008-2245), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.