← back
CVE-2026-21693highCWE-20CWE-681CWE-754CWE-843

iccDEV has Type Confusion in CIccSegmentedCurveXml::ToXml() at IccXML/IccLibXML/IccMpeXml.cpp

21Vexday Risk Score

No sign of exploitation. No public exploitation artifact known so far.

ssvc Trackcvss 8.8epss 0.4%
exploitation probability
0.4%top 70% of all CVEs
observed exploitation
nono source reports it
In short

iccDEV library has a type confusion bug in its color profile processing code that can cause the program to crash or behave unpredictably when handling certain ICC color profiles. This affects anyone using iccDEV to work with color management files.

Technical detail

A type confusion vulnerability in CIccSegmentedCurveXml::ToXml() allows an attacker to craft a malicious ICC color profile that triggers incorrect type handling during XML serialization. The vulnerability requires processing of a specially crafted ICC profile file and can lead to denial of service or memory corruption.

Summary generated and translated by AI from the official description.
iccDEV provides a set of libraries and tools that allow for the interaction, manipulation, and application of International Color Consortium (ICC) color management profiles. Versions prior to 2.3.1.2 have a Type Confusion vulnerability in `CIccSegmentedCurveXml::ToXml()` at `IccXML/IccLibXML/IccMpeXml.cpp`. This vulnerability affects users of the iccDEV library who process ICC color profiles. Version 2.3.1.2 contains a patch. No known workarounds are available.
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H