CVE-2020-1179: Windows GDI Information Disclosure Vulnerability
An information disclosure vulnerability exists when the Windows GDI component improperly discloses the contents of its memory, aka 'Windows GDI Information Disclosure Vulnerability'. This CVE ID is unique from CVE-2020-0963, CVE-2020-1141, CVE-2020-1145.
Other sources
An information disclosure vulnerability exists when the Windows GDI component improperly discloses the contents of its memory. An attacker who successfully exploited the vulnerability could obtain information to further compromise the user’s system. There are multiple ways an attacker could exploit the vulnerability, such as by convincing a user to open a specially crafted document, or by convincing a user to visit an untrusted webpage. The security update addresses the vulnerability by correcting how the Windows GDI component handles objects in memory.
— Microsoft
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Patch KB4556843 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Patch KB4556852 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Patch KB4551853 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Patch KB4556807 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Patch KB4556853 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Patch KB4556846 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Patch KB4556813 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Patch KB4556826 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Patch KB4556799 - Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Patch KB4556812
Event History
Frequently Asked Questions
What is the severity of CVE-2020-1179?
CVE-2020-1179 has a severity rating of Important, indicating a significant risk of information disclosure.
How do I fix CVE-2020-1179?
To mitigate CVE-2020-1179, apply the latest security updates provided by Microsoft for affected Windows versions.
What version of Windows is affected by CVE-2020-1179?
CVE-2020-1179 affects multiple versions of Windows, including Windows 7, 8.1, 10, and various Windows Server editions.
What type of attack can exploit CVE-2020-1179?
CVE-2020-1179 can be exploited through crafted applications that lead to unauthorized memory access and information disclosure.
Is there a workaround for CVE-2020-1179?
Currently, the recommended mitigation for CVE-2020-1179 is to install security updates as there are no known effective workarounds.