#VU14394 Memory corruption in Windows Server and Windows - CVE-2018-8397
Published: August 14, 2018 / Updated: August 14, 2018
Windows Server
Windows
Microsoft
Description
The vulnerability allows a remote attacker to execute arbitrary code on the target system.
The vulnerability exists due to improper handling of objects in memory by Windows GDI component. A remote attacker can trick the victim into visiting a specially crafted website or opening malicious content, trigger memory corruption and execute arbitrary code with elevated privileges.
Successful exploitation of the vulnerability may result in system compromise.