Microsoft Knowledge Base Email Alertz

MS08-046: Vulnerabilities in Microsoft Windows Image Color Management could allow remote code execution

Search KbAlertz

Advanced Search

Receive Microsoft Knowledge Base articles by E-Mail?

Every night we scan the Microsoft Knowledge Base. If technologies you're interested in are updated, we'll send you an e-mail. You only get one e-mail a day, and only when new articles are added.

Click here to create a
FREE account
Already have an account?
[Click here to Login]











Microsoft Knowledge Base Article

This article contents is Microsoft Copyrighted material.
©2005-©2007 Microsoft Corporation. All rights reserved. Terms of Use | Trademarks

Article ID: 952954 - Last Review: September 30, 2011 - Revision: 2.0

MS08-046: Vulnerabilities in Microsoft Windows Image Color Management could allow remote code execution

System TipThis article applies to a different version of Windows than the one you are using. Content in this article may not be relevant to you. Visit the Windows Vista Solution Center

On This Page

INTRODUCTION

Microsoft has released security bulletin MS08-046. To view the complete security bulletin, visit one of the following Microsoft Web sites:

How to obtain help and support for this security update

For home users, no-charge support is available by calling 1-866-PCSAFETY in the United States and Canada or by contacting your local Microsoft subsidiary. For more information about how to contact your local Microsoft subsidiary for support issues with security updates, visit the Microsoft International Support Web site:
http://support.microsoft.com/common/international.aspx?rdpath=4 (http://support.microsoft.com/common/international.aspx?rdpath=4)
North American customers can also obtain instant access to unlimited no-charge e-mail support or to unlimited individual chat support by visiting the following Microsoft Web site:
http://support.microsoft.com/oas/default.aspx?&prid=7552 (http://support.microsoft.com/oas/default.aspx?&prid=7552)
For enterprise customers, support for security updates is available through your usual support contacts.

File information

The English (United States) version of this security update has the file attributes (or later file attributes) that are listed in the following table. The dates and times for these files are listed in Coordinated Universal Time (UTC). When you view the file information, it is converted to local time. To find the difference between UTC and local time, use the Time Zone tab in the Date and Time item in Control Panel.

For all supported editions of Windows 2000

Collapse this tableExpand this table
File nameFile versionFile sizeDateTimePlatform
Mscms.dll5.0.2195.716269,90425-Jun-200822:21x86

Windows XP and Windows Server 2003 file information notes

  • The files that apply to a specific milestone (RTM, SPn) and service branch (QFE, GDR) are noted in the SP requirement and Service branch columns.
  • GDR service branches contain only fixes that are broadly released to address widespread, critical issues. QFE service branches contain hotfixes in addition to broadly released fixes.
  • In addition to the files that are listed in these tables, this software update also installs an associated security catalog file (Microsoft Knowledge Base article number.cat) that is signed by using a Microsoft digital signature.
For all supported 32-bit editions of Windows XP
Collapse this tableExpand this table
File nameFile versionFile sizeDateTimePlatformSP requirementService branch
Mscms.dll5.1.2600.339674,24024-Jun-200816:23x86SP2SP2GDR
Mscms.dll5.1.2600.339674,24024-Jun-200816:28x86SP2SP2QFE
Mscms.dll5.1.2600.562774,24024-Jun-200816:43x86SP3SP3GDR
Mscms.dll5.1.2600.562774,24024-Jun-200816:53x86SP3SP3QFE
For all supported x64-based editions of Windows XP and all supported x64-based editions of Windows Server 2003
Collapse this tableExpand this table
File nameFile versionFile sizeDateTimePlatformSP requirementService branch
Mscms.dll5.2.3790.3163154,11226-Jun-200801:18x64SP1SP1GDR
Wmscms.dll5.2.3790.316375,26426-Jun-200801:18x86SP1SP1GDR\WOW
Mscms.dll5.2.3790.3163154,11226-Jun-200801:18x64SP1SP1QFE
Wmscms.dll5.2.3790.316375,26426-Jun-200801:18x86SP1SP1QFE\WOW
Mscms.dll5.2.3790.4320174,59226-Jun-200801:29x64SP2SP2GDR
Wmscms.dll5.2.3790.432077,82426-Jun-200801:29x86SP2SP2GDR\WOW
Mscms.dll5.2.3790.4320174,59226-Jun-200801:18x64SP2SP2QFE
Wmscms.dll5.2.3790.432077,82426-Jun-200801:18x86SP2SP2QFE\WOW
For all supported 32-bit editions of Windows Server 2003
Collapse this tableExpand this table
File nameFile versionFile sizeDateTimePlatformSP requirementService branch
Mscms.dll5.2.3790.316375,26425-Jun-200814:24x86SP1SP1GDR
Mscms.dll5.2.3790.316375,26425-Jun-200814:30x86SP1SP1QFE
Mscms.dll5.2.3790.432077,82425-Jun-200813:53x86SP2SP2GDR
Mscms.dll5.2.3790.432077,82425-Jun-200814:43x86SP2SP2QFE
For all supported Itanium-based editions of Windows Server 2003
Collapse this tableExpand this table
File nameFile versionFile sizeDateTimePlatformSP requirementService branch
Mscms.dll5.2.3790.3163228,86426-Jun-200801:17IA-64SP1SP1GDR
Wmscms.dll5.2.3790.316375,26426-Jun-200801:17x86SP1SP1GDR\WOW
Mscms.dll5.2.3790.3163228,86426-Jun-200801:17IA-64SP1SP1QFE
Wmscms.dll5.2.3790.316375,26426-Jun-200801:17x86SP1SP1QFE\WOW
Mscms.dll5.2.3790.4320220,67226-Jun-200801:18IA-64SP2SP2GDR
Wmscms.dll5.2.3790.432077,82426-Jun-200801:19x86SP2SP2GDR\WOW
Mscms.dll5.2.3790.4320220,67226-Jun-200801:17IA-64SP2SP2QFE
Wmscms.dll5.2.3790.432077,82426-Jun-200801:17x86SP2SP2QFE\WOW

APPLIES TO
  • Microsoft Windows Server 2003 R2 Standard x64 Edition
  • Microsoft Windows Server 2003, Datacenter x64 Edition
  • Microsoft Windows Server 2003 Service Pack 2, when used with:
    • Microsoft Windows Server 2003, Datacenter Edition (32-bit x86)
    • Microsoft Windows Server 2003, Datacenter x64 Edition
    • Microsoft Windows Server 2003 R2 Standard x64 Edition
    • Microsoft Windows XP Professional x64 Edition
  • Microsoft Windows Server 2003, Datacenter Edition (32-bit x86)
  • Microsoft Windows XP Media Center Edition 2005
  • Microsoft Windows XP Professional x64 Edition
  • Microsoft Windows XP Service Pack 3, when used with:
    • Microsoft Windows XP Professional
    • Microsoft Windows XP Home Edition
  • Microsoft Small Business Server 2000 Standard Edition
Keywords: 
kbfix kbbug kbsecvulnerability kbsecbulletin kbsecurity kbqfe kbexpertisebeginner KB952954
       

Community Feedback System

Very often, it takes hours to solve a problem. Very often, you've looked high and low, and have tried a lot of solutions. When you finally found it, chances are, it was because someone else helped you. Here's your chance to give back. Use our community feedback tool to let others know what worked for you and what didn't.

Please also understand that the community feedback system is not warranted to be correct, it's simply a system that we've built to let people try and help each other. If something in a feedback response doesn't make sense to you, or you're not comfortable making changes that the feedback talks about (like registry edits), please consult a professional.

Thank you for using kbAlertz.com Feedback System.

-- Scott Cate