CVE-2018-0750

LOW

Description

The Windows GDI component in Windows 7 SP1 and Windows Server 2008 SP2 and R2 SP1 allows an information disclosure vulnerability due to the way objects are handled in memory, aka "Windows Elevation of Privilege Vulnerability".

References

http://www.securityfocus.com/bid/102357

http://www.securitytracker.com/id/1040091

https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2018-0750

Details

Source: MITRE

Published: 2018-01-04

Updated: 2018-01-12

Type: CWE-200

Risk Information

CVSS v2.0

Base Score: 2.1

Vector: AV:L/AC:L/Au:N/C:P/I:N/A:N

Impact Score: 2.9

Exploitability Score: 3.9

Severity: LOW

CVSS v3.0

Base Score: 5.5

Vector: CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

Impact Score: 3.6

Exploitability Score: 1.8

Severity: MEDIUM