Executive brief
The Graphics Device Interface (GDI) in Microsoft Windows contains a privilege escalation vulnerability that allows local users to gain elevated privileges via a crafted application. This vulnerability has been observed being exploited in the wild.
Affected products
- Microsoft Windows Vista SP2
- Microsoft Windows Server 2008 SP2, R2 SP1
- Microsoft Windows 7 SP1
- Microsoft Windows 8.1 -
- Microsoft Windows Server 2012 Gold, R2
- Microsoft Windows RT 8.1 -
- Microsoft Windows 10 Gold, 1511, 1607
Timeline
- 2017-03-14: patched: MSRC advisory published date (implied by CVE year and reference links)
- 2017-03-27: disclosed: Technical blog post regarding detection and mitigation published.
- 2022-05-24: kev added: Added to CISA Known Exploited Vulnerabilities Catalog.