Executive brief
A remote code execution vulnerability exists in the Windows Graphics Device Interface (GDI) due to improper handling of objects in memory. An attacker could exploit this to take full control of an affected system, typically requiring a user to open a specially crafted file or visit a malicious website.
Affected products
- Microsoft Windows 7 Service Pack 1
- Microsoft Windows 8.1 -
- Microsoft Windows RT 8.1 -
- Microsoft Windows 10 1507, 1607, 1703, 1709, 1803, 1809, 1903
- Microsoft Windows Server 2008 Service Pack 2, R2 Service Pack 1
- Microsoft Windows Server 2012 -, R2
- Microsoft Windows Server 2016 -, 1803, 1903
- Microsoft Windows Server 2019 -
Timeline
- 2019-05-16: disclosed: Initial analysis by NIST
- 2022-03-25: kev added: Added to CISA Known Exploited Vulnerabilities Catalog