cbcvebase.
CVE-2020-1435
published 2020-07-14

CVE-2020-1435: A remote code execution vulnerability exists in the way that the Windows Graphics Device Interface (GDI) handles objects in the memory, aka 'GDI+ Remote Code…

PriorityP356high8.8CVSS 3.1
AVNACLPRNUIRSUCHIHAH
EPSS
13.79%
96.1th percentile
A remote code execution vulnerability exists in the way that the Windows Graphics Device Interface (GDI) handles objects in the memory, aka 'GDI+ Remote Code Execution Vulnerability'.

Affected

70 ranges· showing 25
VendorProductVersion rangeFixed in
microsoftwindows
microsoftwindows
microsoftwindows
microsoftwindows
microsoftwindows
microsoftwindows
microsoftwindows
microsoftwindows
microsoftwindows
microsoftwindows
microsoftwindows
microsoftwindows
microsoftwindows
microsoftwindows
microsoftwindows
microsoftwindows
microsoftwindows
microsoftwindows
microsoftwindows_10
microsoftwindows_10
microsoftwindows_10
microsoftwindows_10
microsoftwindows_10
microsoftwindows_10
microsoftwindows_10

Detection & IOCsextracted from sources · hover to see the quote

  • Exploit delivery via specially crafted website — monitor for suspicious web-based content triggering GDI+ processing (e.g., malformed image files loaded in browser context)
  • Exploit delivery via specially crafted document file — monitor for Office/document files that invoke GDI+ object processing, particularly from email attachments or file shares
  • Successful exploitation results in full system control — monitor for unexpected child processes, new account creation, or privilege escalation following GDI+ component activity
  • ·Exploit status is assessed as 'Exploitation Less Likely' for both latest and older software releases, and has not been publicly disclosed or exploited in the wild at time of advisory
  • ·Users with limited account rights are less impacted; prioritize patching for systems where users operate with administrative privileges

CVSS provenance

nvdv3.18.8HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
nvdv2.09.3CRITICALAV:N/AC:M/Au:N/C:C/I:C/A:C
vendor_msrc6.3MEDIUM
Stop checking back — get the weekly exploitation signal.

Every Monday: what got weaponized or added to CISA KEV in the last seven days — each CVE cross-linked to its PoC, Nuclei template, and detection rule. Free, one email a week, unsubscribe in one click.