← Back

CVE-2019-1154

nvd nist
Published: Aug 14, 2019Modified: Feb 20, 2026

JSON object

Loading...
5.5
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Exploitability: 1.8 / Impact: 3.6
Source: secure@microsoft.com (Secondary)

Description

An information disclosure vulnerability exists when the Windows GDI component improperly discloses the contents of its memory. An attacker who successfully exploited the vulnerability could obtain information to further compromise a user’s system. There are multiple ways an attacker could exploit the vulnerability, such as by convincing a user to open a specially crafted document or by convincing a user to visit an untrusted webpage. The update addresses the vulnerability by correcting how the Windows GDI component handles objects in memory.

Affected (4)

2 products
Windows 7
Windows Server 2008
Configuration A
4 vulnerable
Vulnerable SoftwareAffected Versions
All versions
Microsoft
All versions
Version r2 sp1
Version r2 sp1

References (2)

Source: af854a3a-2127-422b-91ae-364da2661108
PatchVendor Advisory

Timeline

No history available yet.