cbcvebase.
CVE-2018-8397
published 2018-08-15

CVE-2018-8397: A remote code execution vulnerability exists in the way that the Windows Graphics Device Interface (GDI) handles objects in the memory, aka "GDI+ Remote Code…

PriorityP264high8.8CVSS 3.0
AVNACLPRNUIRSUCHIHAH
EPSS
67.87%
99.2th percentile
A remote code execution vulnerability exists in the way that the Windows Graphics Device Interface (GDI) handles objects in the memory, aka "GDI+ Remote Code Execution Vulnerability." This affects Windows Server 2008, Windows 7, Windows Server 2008 R2.

Affected

18 ranges
VendorProductVersion rangeFixed in
microsoftwindows_7
microsoftwindows_7
microsoftwindows_server_2008
microsoftwindows_server_2008
microsoftwindows_server_2008
microsoftwindows_server_2008
microsoftwindows_server_2008
microsoftwindows_server_2008
microsoftwindows_server_2008_r2
microsoftwindows_server_2008_r2
microsoftwindows_server_2008_r2
msrcwindows_7_for_32-bit_systems_service_pack_1
msrcwindows_7_for_x64-based_systems_service_pack_1
msrcwindows_server_2008_for_32-bit_systems_service_pack_2
msrcwindows_server_2008_for_itanium-based_systems_service_pack_2
msrcwindows_server_2008_for_x64-based_systems_service_pack_2
msrcwindows_server_2008_r2_for_itanium-based_systems_service_pack_1
msrcwindows_server_2008_r2_for_x64-based_systems_service_pack_1

Detection & IOCsextracted from sources · hover to see the quote

  • Exploit vector is a specially crafted website or document file targeting Windows GDI+ object handling in memory; monitor for suspicious document opens or web-based content delivery leading to GDI-related crashes or code execution on Windows Server 2008, Windows 7, or Windows Server 2008 R2.
  • Monitor for exploitation attempts via web-based delivery: attacker-hosted pages designed to trigger GDI+ memory mishandling; watch for browser or document renderer processes spawning unexpected child processes on affected OS versions.
  • ·No public exploit or active in-the-wild exploitation reported at time of advisory; exploitation rated 'Less Likely' for older software releases.

CVSS provenance

nvdv3.08.8HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.09.3CRITICALAV:N/AC:M/Au:N/C:C/I:C/A:C
vendor_msrc8.8HIGH
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.