CVE-2019-0618: Critical severity windows 10 vulnerability
Published Mar 5, 2019
·Updated
A remote code execution vulnerability exists in the way that the Windows Graphics Device Interface (GDI) handles objects in the memory, aka 'GDI+ Remote Code Execution Vulnerability'. This CVE ID is unique from CVE-2019-0662.
Affected Software
18 affected components
Microsoft Windows 10
Microsoft Windows 10=1607
Microsoft Windows 10=1703
Microsoft Windows 10=1709
Microsoft Windows 10=1803
Microsoft Windows 10=1809
Microsoft Windows 7=sp1
Microsoft Windows 8.1
Microsoft Windows RT 8.1
Microsoft Windows Server 2008=sp2
Microsoft Windows Server 2008=r2-sp1
Microsoft Windows Server 2008=r2-sp1
Microsoft Windows Server 2012
Microsoft Windows Server 2012=r2
Microsoft Windows Server 2016
Microsoft Windows Server 2016=1709
Microsoft Windows Server 2016=1803
Microsoft Windows Server 2019
Remediation
Event History
Mar 5, 2019
CVE Published
11:29 PM
Mar 6, 2019
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
DescriptionWeakness
Frequently Asked Questions
1
What is the severity of CVE-2019-0618?
CVE-2019-0618 is rated as critical due to its potential for remote code execution.
2
How do I fix CVE-2019-0618?
To fix CVE-2019-0618, apply the security update provided by Microsoft for the affected Windows versions.
3
What versions of Windows are affected by CVE-2019-0618?
CVE-2019-0618 affects multiple Windows versions including Windows 7, Windows 8.1, Windows 10, and various versions of Windows Server.
4
Can CVE-2019-0618 be exploited remotely?
Yes, CVE-2019-0618 can be exploited remotely by an attacker without authentication.
5
What are the consequences of an exploit for CVE-2019-0618?
An exploit of CVE-2019-0618 could allow an attacker to run arbitrary code on the affected system.