CVE-2019-0903: Microsoft GDI Remote Code Execution Vulnerability
A remote code execution vulnerability exists in the way that the Windows Graphics Device Interface (GDI) handles objects in the memory, aka 'GDI+ Remote Code Execution Vulnerability'.
Other sources
A remote code execution vulnerability exists in the way that the Windows Graphics Device Interface (GDI) handles objects in the memory. An attacker who successfully exploited this vulnerability could take control of the affected system.
— CISA
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2019-0903?
CVE-2019-0903 has a critical severity level due to its potential for remote code execution.
How do I fix CVE-2019-0903?
To fix CVE-2019-0903, users should apply the latest security updates provided by Microsoft for affected Windows versions.
Which software is affected by CVE-2019-0903?
CVE-2019-0903 affects Microsoft Windows 10, Windows 7, Windows 8.1, and various versions of Windows Server.
Can CVE-2019-0903 be exploited remotely?
Yes, CVE-2019-0903 can be exploited remotely without authentication, allowing attackers to execute arbitrary code.
What systems are impacted by CVE-2019-0903?
CVE-2019-0903 impacts systems running Microsoft Graphics Device Interface (GDI) across multiple Windows operating systems.