CVE-2019-0903 — Microsoft GDI Remote Code Execution Vulnerability
CVE-2019-0903: Microsoft GDI Remote Code Execution Vulnerability
CISA Known Exploited Vulnerability (KEV)
| Vendor / project | Microsoft |
| Product | Graphics Device Interface (GDI) |
| Date added | 2022-03-25 |
| Due date | 2022-04-15 |
| Ransomware campaign use | Unknown |
Description
A remote code execution vulnerability exists in the way that the Windows Graphics Device Interface (GDI) handles objects in the memory. An attacker who successfully exploited this vulnerability could take control of the affected system.
Required action (CISA)
Apply updates per vendor instructions.
Notes
https://nvd.nist.gov/vuln/detail/CVE-2019-0903
References
- NVD: https://nvd.nist.gov/vuln/detail/CVE-2019-0903
- KEV catalog: https://www.cisa.gov/known-exploited-vulnerabilities-catalog