PT-2026-1395 · Iccdev · Iccdev

Xsscx

·

Published

2026-01-06

·

Updated

2026-01-07

·

CVE-2026-21675

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions iccDEV versions prior to 2.3.1.1
Description iccDEV is a set of libraries and tools for working with ICC color management profiles. Versions 2.3.1 and below contain a Use After Free issue in the CIccXform::Create() function. The function deletes the hint manager object without proper cleanup, which can be exploited for Remote Code Execution (RCE) in any application using the library.
Recommendations Update to version 2.3.1.1 or later.

Exploit

Fix

RCE

Use After Free

Weakness Enumeration

Related Identifiers

CVE-2026-21675
GHSA-WCWX-794G-G78F

Affected Products

Iccdev