VDB

CVE-2020-0643

CVE-2020-0643 PUBLISHED CVSS 5.5 MEDIUM

An information disclosure vulnerability exists in the way that the Windows Graphics Device Interface Plus (GDI+) handles objects in memory, allowing an attacker to retrieve information from a targeted system, aka 'Windows GDI+ Information Disclosure Vulnerability'.

EPSS 0.88% · 75.8th percentile

Risk Scores

CVSS 3.1
5.5
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
EPSS Score
0.88%
75.8th percentile

Affected Products

VendorProductVersions
microsoftwindows_server_2012r2
MicrosoftWindows Server, version 1909 (Server Core installation)*
MicrosoftWindows Server*, version 1803 (Core Installation), 2019 (Core installation)
microsoftwindows_rt_8.1
microsoftwindows_server_2008r2, r2
microsoftwindows_101607, 1709, 1909
MicrosoftWindows 10 Version 1909 for x64-based Systemsunspecified
MicrosoftWindows 10 Version 1903 for 32-bit Systemsunspecified
MicrosoftWindows 10 Version 1903 for x64-based Systems*
microsoftwindows_7
MicrosoftWindows 10 Version 1909 for ARM64-based Systemsunspecified
MicrosoftWindows Server, version 1903 (Server Core installation)unspecified
MicrosoftWindows 10 Version 1909 for 32-bit Systemsunspecified
microsoftwindows_8.1
MicrosoftWindows 10 Version 1903 for ARM64-based Systemsunspecified
microsoftwindows_server_20161803, 1909
microsoftwindows_server_2019
MicrosoftWindows7 for 32-bit Systems Service Pack 1, 8.1 for x64-based systems, RT 8.1

Timeline

  • May 23, 2014 PoC Published
  • Jan 14, 2020 CVE Published
  • Jan 21, 2020 PoC Published
  • Jun 26, 2020 PoC Published
  • Apr 14, 2021 EPSS Score
  • Jun 23, 2021 EPSS Score
  • Aug 24, 2021 EPSS Score
  • Oct 26, 2021 EPSS Score
  • Jan 6, 2022 EPSS Score
  • Feb 4, 2022 EPSS Score
  • Feb 28, 2022 EPSS Score
  • May 1, 2022 EPSS Score
Open in Interactive Console →
$ Console Community · 100/wk Open console ›