PT-2018-1585 · Microsoft · Windows 7+3
Vladislav Stolyarov
·
Published
2018-09-11
·
Updated
2018-11-25
·
CVE-2018-8422
CVSS v3.1
6.5
Medium
| Vector | AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Windows GDI versions prior to the fixed version
Windows 7
Windows Server 2008 R2
Description
The issue is caused by a buffer overflow in the Windows GDI component, allowing an attacker to disclose protected information using a specially crafted document. This can lead to the exposure of sensitive information.
Recommendations
For Windows 7 and Windows Server 2008 R2, update to a version that includes the fix for this issue.
As a temporary workaround, consider restricting access to sensitive documents until a patch is available.
Avoid using the Windows GDI component with untrusted documents until the issue is resolved.
Fix
Buffer Overflow
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Windows
Windows 7
Windows Gdi
Windows Server 2008 R2