PT-2026-4549 · Iccdev · Iccdev

Xsscx

·

Published

2026-01-24

·

Updated

2026-01-25

·

CVE-2026-24407

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions iccDEV versions prior to 2.3.1.2
Description The iccDEV software, which provides libraries and tools for interacting with ICC color management profiles, contains an issue in the icSigCalcOp() function. User-controllable input is unsafely incorporated into ICC profile data or other structured binary blobs, leading to undefined behavior. Successful exploitation could result in denial of service, data manipulation, bypassing application logic, and potentially code execution.
Recommendations Update to version 2.3.1.2 or later.

Exploit

Fix

DoS

RCE

Weakness Enumeration

Related Identifiers

CVE-2026-24407
GHSA-M6GX-93CP-4855

Affected Products

Iccdev