cbcvebase.
CVE-2018-8595
published 2018-12-12

CVE-2018-8595: An information disclosure vulnerability exists when the Windows GDI component improperly discloses the contents of its memory, aka "Windows GDI Information…

PriorityP275medium6.5CVSS 3.0
AVNACLPRNUIRSUCHINAN
ITWVulnCheck KEV
Exploited in the wild
EPSS
6.73%
93.2th percentile
An information disclosure vulnerability exists when the Windows GDI component improperly discloses the contents of its memory, aka "Windows GDI Information Disclosure Vulnerability." This affects Windows 7, Windows Server 2012 R2, Windows RT 8.1, Windows Server 2008, Windows Server 2019, Windows Server 2012, Windows 8.1, Windows Server 2016, Windows Server 2008 R2, Windows 10, Windows 10 Servers. This CVE ID is unique from CVE-2018-8596.

Affected

59 ranges· showing 25
VendorProductVersion rangeFixed in
microsoftwindows_10
microsoftwindows_10
microsoftwindows_10
microsoftwindows_10
microsoftwindows_10
microsoftwindows_10
microsoftwindows_10
microsoftwindows_10
microsoftwindows_10
microsoftwindows_10
microsoftwindows_10
microsoftwindows_10
microsoftwindows_10
microsoftwindows_10
microsoftwindows_10
microsoftwindows_10
microsoftwindows_10
microsoftwindows_10
microsoftwindows_10
microsoftwindows_10
microsoftwindows_10_servers
microsoftwindows_10_servers
microsoftwindows_7
microsoftwindows_7
microsoftwindows_8.1

Detection & IOCsextracted from sources · hover to see the quote

  • Exploitation vector involves convincing a user to open a specially crafted document or visit an untrusted webpage, triggering improper memory disclosure in the Windows GDI component
  • The vulnerability leaks memory layout information (ASLR bypass potential), enabling an attacker to predict memory addressing for follow-on exploitation
  • ·Exploit status is rated 'Exploitation More Likely' for both latest and older software releases, despite no confirmed public exploit or in-the-wild exploitation at time of advisory
  • ·CVE-2018-8595 and CVE-2018-8596 are distinct but related Windows GDI Information Disclosure vulnerabilities patched in the same update cycle; ensure both are addressed

CVSS provenance

nvdv3.06.5MEDIUMCVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N
nvdv2.04.3MEDIUMAV:N/AC:M/Au:N/C:P/I:N/A:N
vulncheck6.5MEDIUM
vendor_msrc4.7MEDIUM
CVEs like this are exactly what “Exploited This Week” covers.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.