CVE-2019-1098

MEDIUM

Windows 7 and Windows Server 2008 - Information Disclosure in GDI Component

Title source: llm
STIX 2.1

Description

An information disclosure vulnerability exists when the Windows GDI component improperly discloses the contents of its memory, aka 'Windows GDI Information Disclosure Vulnerability'. This CVE ID is unique from CVE-2019-1094, CVE-2019-1095, CVE-2019-1099, CVE-2019-1100, CVE-2019-1101, CVE-2019-1116.

References (1)

Core 1
Core References

Scores

CVSS v3 6.5
EPSS 0.0673
EPSS Percentile 93.1%
Attack Vector NETWORK
CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N

Details

CWE
CWE-200
Status published
Products (3)
microsoft/windows_7
microsoft/windows_server_2008 (2 CPE variants)
microsoft/windows_server_2008 r2 sp1
Published Jul 15, 2019
Tracked Since Feb 18, 2026