CVE-2019-0903highunder attack

CVE-2019-0903: high-severity vulnerability in Microsoft Windows

Published · Updated

56Vexday Risk Score

Prioritize patching. It under exploitation confirmed by CISA.

ssvc Actcvss 8.8epss 22%
from disclosure to weapon
Published on NVDMay 16
CISA KEV+1044d
exploitation probability
22%top 2% of all CVEs
observed exploitation
yesCISA + VulnCheck
Action required by CISAfederal deadline: 2022-04-15

Apply updates per vendor instructions.

In short

A flaw in Windows GDI (graphics system) allows attackers to run malicious code on your computer by crafting a specially designed image or document. This is dangerous because it can happen just by opening a file or visiting a webpage.

Technical detail

Remote code execution vulnerability in Windows GDI object memory handling allows unauthenticated attackers to execute arbitrary code via malicious graphics content. Attack vector is network-based (image/document files); pre-condition requires user interaction to open crafted file. Impact includes complete system compromise with attacker privileges.

Summary generated and translated by AI from the official description.

The full analysis of this CVE is available in Portuguese →

A remote code execution vulnerability exists in the way that the Windows Graphics Device Interface (GDI) handles objects in the memory, aka 'GDI+ Remote Code Execution Vulnerability'.
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H