ZeroHour

CVE-2019-0903

KEVmass

Remote Code Execution in Microsoft Windows Graphics Device Interface (GDI)

CISA: Microsoft GDI Remote Code Execution Vulnerability

CVSS 3.1
8.8 high
EPSS
22%p97
Published
()
KEV added
AI analysis

CVE-2019-0903 is a remote code execution vulnerability in the way the Windows Graphics Device Interface (GDI) handles objects in memory, allowing an attacker who successfully exploits it to take control of the affected system. GDI is a core Windows component, so the flaw is triggered wherever the operating system processes graphics objects, making effectively all Windows installations potential targets. Successful exploitation grants the attacker the ability to run arbitrary code with the privileges of the affected process and take control of the system. Any organization running Windows with the vulnerable GDI component is affected. The vulnerability is confirmed to be exploited in the wild, having been added to the CISA Known Exploited Vulnerabilities catalog on 2022-03-25, and it carries a 21.7% probability of exploitation in the next 30 days (97th percentile EPSS).

What to do: Apply Microsoft security updates for GDI per vendor instructions, as required by CISA's KEV listing, prioritizing systems that handle untrusted content such as documents, fonts, and web graphics. Verify via Windows Update/WSUS or patch management tooling that the relevant Windows security update has been applied to all endpoints and servers, since GDI is present on every Windows machine. Because the vulnerability is confirmed exploited in the wild, treat patching as urgent across the full Windows estate.

Affected
Microsoft Graphics Device Interface (GDI)
Estimated exposure
masshundreds of millions of Windows systems (GDI ships with essentially every Windows desktop and server) — GDI is a foundational Windows graphics component included in every Windows installation, so exposure is on the order of the entire Windows install base rather than a discrete product population.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

A remote code execution vulnerability exists in the way that the Windows Graphics Device Interface (GDI) handles objects in the memory, aka 'GDI+ Remote Code Execution Vulnerability'.

CISA Known Exploited Vulnerability
Affected
Microsoft Graphics Device Interface (GDI)
Required action
Apply updates per vendor instructions.
Due date
Ransomware use
Unknown
Vendors
microsoft
Products
windows 10 1507, windows 10 1607, windows 10 1703, windows 10 1709, windows 10 1803, windows 10 1809, windows 10 1903, windows 7, windows 8.1, windows rt 8.1, windows server 1803, windows server 1903
Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

In the news

No ingested article mentions this CVE yet.