CVE-2019-0903CISA KEV
Microsoft GDI Remote Code Execution Vulnerability
CISA lists this Microsoft vulnerability as known exploited. Its MSRC release detail is outside this installation's collected history.
CISA catalog record
A remote code execution vulnerability exists in the way that the Windows Graphics Device Interface (GDI) handles objects in the memory. An attacker who successfully exploited this vulnerability could take control of the affected system.
- Product
- Graphics Device Interface (GDI)
- Added to KEV
- 25 Mar 2022
- Federal remediation due
- 15 Apr 2022
- Known ransomware use
- Not reported