#VU47543 Out-of-bounds read in Windows and Windows Server - CVE-2020-16914
Published: October 13, 2020
Windows
Windows Server
Microsoft
Description
The vulnerability allows a local user to gain access to potentially sensitive information.
The vulnerability exists due to the way that the Windows Graphics Device Interface Plus (GDI+) handles objects in memory. A local user can use a specially crafted application, trigger out-of-bounds read error and read contents of memory on the system.