CVE-2020-0643 PUBLISHED CVSS 5.5 MEDIUM

An information disclosure vulnerability exists in the way that the Windows Graphics Device Interface Plus (GDI+) handles objects in memory, allowing an attacker to retrieve information from a targeted system, aka 'Windows GDI+ Information Disclosure Vulnerability'.

EPSS 0.88% · 75.2th percentile

Risk Scores

CVSS v3.1
5.5
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
EPSS Score
0.88%
75.2th percentile

Affected Products

VendorProductVersions
microsoftwindows_server_2012r2
MicrosoftWindows Server, version 1909 (Server Core installation)unspecified
MicrosoftWindows Server2008 R2 for x64-based Systems Service Pack 1, 2019, 2019 (Core installation)
microsoftwindows_rt_8.1
microsoftwindows_server_2008r2, r2
microsoftwindows_101909, 1903, 1809
MicrosoftWindows 10 Version 1909 for x64-based Systemsunspecified
MicrosoftWindows 10 Version 1903 for 32-bit Systemsunspecified
MicrosoftWindows 10 Version 1903 for x64-based Systemsunspecified
microsoftwindows_7
MicrosoftWindows 10 Version 1909 for ARM64-based Systemsunspecified
MicrosoftWindows Server, version 1903 (Server Core installation)unspecified
MicrosoftWindows 10 Version 1909 for 32-bit Systemsunspecified
microsoftwindows_8.1
MicrosoftWindows 10 Version 1903 for ARM64-based Systemsunspecified
microsoftwindows_server_20161803, 1909
microsoftwindows_server_2019
MicrosoftWindows7 for 32-bit Systems Service Pack 1, 10 Version 1607 for x64-based Systems, 10 Version 1607 for 32-bit Systems

Timeline

References

Open in Interactive Console →