CVE-2019-1046: Windows GDI Information Disclosure Vulnerability
An information disclosure vulnerability exists when the Windows GDI component improperly discloses the contents of its memory, aka 'Windows GDI Information Disclosure Vulnerability'. This CVE ID is unique from CVE-2019-0968, CVE-2019-0977, CVE-2019-1009, CVE-2019-1010, CVE-2019-1011, CVE-2019-1012, CVE-2019-1013, CVE-2019-1015, CVE-2019-1016, CVE-2019-1047, CVE-2019-1048, CVE-2019-1049, CVE-2019-1050.
Other sources
An information disclosure vulnerability exists when the Windows GDI component improperly discloses the contents of its memory. An attacker who successfully exploited the vulnerability could obtain information to further compromise the user’s system. There are multiple ways an attacker could exploit the vulnerability, such as by convincing a user to open a specially crafted document, or by convincing a user to visit an untrusted webpage. The security update addresses the vulnerability by correcting how the Windows GDI component handles objects in memory.
— Microsoft
Affected Software
Remediation
Event History
Frequently Asked Questions
What is the severity of CVE-2019-1046?
CVE-2019-1046 has a severity rating that indicates it can lead to information disclosure allowing attackers to gain sensitive data.
How do I fix CVE-2019-1046?
To fix CVE-2019-1046, apply the latest security updates provided by Microsoft for the affected versions of Windows.
What versions of Windows are affected by CVE-2019-1046?
CVE-2019-1046 affects multiple versions of Windows including Windows 10, Windows 7, and various Windows Server editions.
What type of vulnerability is CVE-2019-1046?
CVE-2019-1046 is classified as an information disclosure vulnerability in the Windows GDI component.
Can CVE-2019-1046 be exploited remotely?
Yes, CVE-2019-1046 can potentially be exploited remotely if the vulnerability is successfully leveraged by an attacker.