Information disclosure in Microsoft Windows and Windows Server - CVE-2018-8239
Published: June 12, 2018 / Updated: June 12, 2018
Vulnerability identifier: #VU13305
CSH Severity: Low
CVSS v4: 5.1 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:A/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N]
CVE-ID: CVE-2018-8239
CWE-ID: CWE-200
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to obtain potentially sensitive information.
The vulnerability exists due to improper handling of objects in memory by Windows GDI component. A remote attacker can trick the victim into visiting a specially crafted website or opening malicious content, trigger memory corruption and obtain information to further compromise the user’s system.
Affected software
Microsoft Windows
Windows Server
Windows Server
How to mitigate CVE-2018-8239
Install updates from vendor's website.