CVE Database
/

CVE-2018-8397

Back to search

CVE-2018-8397

Published: Aug 15, 2018

Modified: Aug 5, 2024

PUBLISHED

Description

A remote code execution vulnerability exists in the way that the Windows Graphics Device Interface (GDI) handles objects in the memory, aka "GDI+ Remote Code Execution Vulnerability." This affects Windows Server 2008, Windows 7, Windows Server 2008 R2.

VendorProductVersions

Microsoft

Windows Server 2008

affected
32-bit Systems Service Pack 2
affected
32-bit Systems Service Pack 2 (Server Core installation)
affected
Itanium-Based Systems Service Pack 2
affected
x64-based Systems Service Pack 2
affected
x64-based Systems Service Pack 2 (Server Core installation)

Microsoft

Windows 7

affected
32-bit Systems Service Pack 1
affected
x64-based Systems Service Pack 1

Microsoft

Windows Server 2008 R2

affected
Itanium-Based Systems Service Pack 1
affected
x64-based Systems Service Pack 1
affected
x64-based Systems Service Pack 1 (Server Core installation)

References

1041460
vdb-entry
x_refsource_SECTRACK
104994
vdb-entry
x_refsource_BID

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now