HomeColorCVE-2026-24407

CVE-2026-24407

HIGH
7.1CVSS
Published: 2026-01-24
Updated: 2026-01-30
AI Analysis

Description

iccDEV provides libraries and tools for interacting with, manipulating, and applying ICC color management profiles. Versions 2.3.1.1 and below have Undefined Behavior in icSigCalcOp(). This occurs when user-controllable input is unsafely incorporated into ICC profile data or other structured binary blobs. Successful exploitation may allow an attacker to perform DoS, manipulate data, bypass application logic and Code Execution. This issue has been fixed in version 2.3.1.2.

CVSS Metrics

Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:N/I:L/A:H
Attack Vector
network
Complexity
low
Privileges
none
User Action
required
Scope
unchanged
Confidentiality
none
Integrity
low
Availability
high
Weaknesses
CWE-20CWE-758

Metadata

Primary Vendor
COLOR
Published
1/24/2026
Last Modified
1/30/2026
Source
NIST NVD
Note: Verify all details with official vendor sources before applying patches.

Affected Products

color : iccdev

AI-Powered Remediation

Generate remediation guidance or a C-suite brief for this vulnerability.

Executive Intelligence Brief