CVE-2019-0903: high-severity vulnerability in Microsoft Windows
Published · Updated
Prioritize patching. It under exploitation confirmed by CISA.
Apply updates per vendor instructions.
A flaw in Windows GDI (graphics system) allows attackers to run malicious code on your computer by crafting a specially designed image or document. This is dangerous because it can happen just by opening a file or visiting a webpage.
Remote code execution vulnerability in Windows GDI object memory handling allows unauthenticated attackers to execute arbitrary code via malicious graphics content. Attack vector is network-based (image/document files); pre-condition requires user interaction to open crafted file. Impact includes complete system compromise with attacker privileges.
The full analysis of this CVE is available in Portuguese →
In the same product, most dangerous first.