Microsoft Windows GDI Information Disclosure Vulnerability

By GIXnews

A vulnerability in the Graphics Device Interface (GDI) component of Microsoft Windows could allow a local attacker to access sensitive information on a targeted system.

The vulnerability is due to improper memory operations that are performed by the affected software. An attacker could exploit this vulnerability by accessing the system and executing an application that submits malicious input to the affected software. A successful exploit could allow the attacker to access sensitive information, which could be used to in conjunction with another vulnerability to execute arbitrary code.

Microsoft confirmed the vulnerability and released software updates.

Security Impact Rating: Low

CVE: CVE-2018-8472

Source:: Cisco Multivendor Vulnerability Alerts