CVE-2020-1248Improper Restriction of Operations within the Bounds of a Memory Buffer in Microsoft Windows 10 Version 1903 FOR 32-bit Systems

Severity
8.8HIGHNVD
EPSS
30.3%
top 3.30%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJun 9
Latest updateMay 24

Description

A remote code execution vulnerability exists in the way that the Windows Graphics Device Interface (GDI) handles objects in the memory, aka 'GDI+ Remote Code Execution Vulnerability'.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:HExploitability: 2.8 | Impact: 5.9

Affected Packages23 packages

Patches

🔴Vulnerability Details

1
GHSA
GHSA-c792-54f9-cgq9: A remote code execution vulnerability exists in the way that the Windows Graphics Device Interface (GDI) handles objects in the memory, aka 'GDI+ Remo2022-05-24

📋Vendor Advisories

1
Microsoft
GDI+ Remote Code Execution Vulnerability2020-06-09

🕵️Threat Intelligence

5
Talos
Microsoft Patch Tuesday for June 2020 — Snort rules and prominent vulnerabilities2020-06-10
Talos
Microsoft Patch Tuesday for June 2020 — Snort rules and prominent vulnerabilities2020-06-10
Qualys
June 2020 Patch Tuesday – 128 Vulns, 11 Critical, Sharepoint, Workstation, Adobe Patches | Qualys2020-06-09
Tenable
Microsoft’s June 2020 Patch Tuesday Addresses 129 CVEs Including Newly Disclosed SMBv3 Vulnerability (CVE-2020-1206)2020-06-09
Qualys
June 2020 Patch Tuesday – 128 Vulns, 11 Critical, Sharepoint, Workstation, Adobe Patches2020-06-09