Vulnerability Name: | CVE-2018-8239 (CCN-144021) | ||||||||||||
Assigned: | 2018-06-12 | ||||||||||||
Published: | 2018-06-12 | ||||||||||||
Updated: | 2018-10-30 | ||||||||||||
Summary: | An information disclosure vulnerability exists when the Windows GDI component improperly discloses the contents of its memory, aka "Windows GDI Information Disclosure Vulnerability." This affects Windows Server 2016, Windows 10, Windows 10 Servers. | ||||||||||||
CVSS v3 Severity: | 5.5 Medium (CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N) 4.8 Medium (Temporal CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C)
3.9 Low (CCN Temporal CVSS v3.1 Vector: CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:N/A:N/E:U/RL:O/RC:C)
| ||||||||||||
CVSS v2 Severity: | 4.3 Medium (CVSS v2 Vector: AV:N/AC:M/Au:N/C:P/I:N/A:N)
| ||||||||||||
Vulnerability Type: | CWE-200 | ||||||||||||
Vulnerability Consequences: | Obtain Information | ||||||||||||
References: | Source: MITRE Type: CNA CVE-2018-8239 Source: BID Type: Third Party Advisory, VDB Entry 104401 Source: CCN Type: BID-104401 Microsoft Windows GDI Component CVE-2018-8239 Information Disclosure Vulnerability Source: SECTRACK Type: Third Party Advisory, VDB Entry 1041102 Source: XF Type: UNKNOWN ms-gdi-cve20188239-info-disc(144021) Source: CCN Type: Microsoft Security TechCenter - June 2018 Windows GDI Information Disclosure Vulnerability Source: CONFIRM Type: Patch, Vendor Advisory https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2018-8239 Source: CCN Type: ZDI-18-581 Microsoft Windows PlayEnhMetaFile Out-Of-Bounds Read Information Disclosure Vulnerability Source: CCN Type: ZDI-18-582 Microsoft Windows PlayEnhMetaFile Out-Of-Bounds Read Information Disclosure Vulnerability Source: CCN Type: ZDI-18-615 Microsoft Internet Explorer EMF Graphic Out-Of-Bounds Read Information Disclosure Vulnerability | ||||||||||||
Vulnerable Configuration: | Configuration 1: Configuration CCN 1: ![]() | ||||||||||||
BACK |