Severity
6.5MEDIUM
EPSS
29.8%
top 3.36%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedJul 14
Latest updateMay 24

Description

An information disclosure vulnerability exists in Windows when the Windows Imaging Component fails to properly handle objects in memory, aka 'Windows Imaging Component Information Disclosure Vulnerability'.

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:NExploitability: 2.8 | Impact: 3.6

Affected Packages13 packages

CVEListV5microsoft/windows18 versions+17
NVDmicrosoft/windows4 versions+3
NVDmicrosoft/windows_107 versions+6
CVEListV5microsoft/windows_server14 versions+13

Patches

🔴Vulnerability Details

4
GHSA
GHSA-wvp2-97x3-gw55: An information disclosure vulnerability exists in Windows when the Windows Imaging Component fails to properly handle objects in memory, aka 'Windows2022-05-24
CVEList
CVE-2020-1397: An information disclosure vulnerability exists in Windows when the Windows Imaging Component fails to properly handle objects in memory, aka 'Windows2020-07-14
GHSA
XSS in Mapfish Print relating to JSONP support2020-07-07
GHSA
XXE attack in Mapfish Print2020-07-07

📋Vendor Advisories

1
Microsoft
Windows Imaging Component Information Disclosure Vulnerability2020-07-14