Lucene search

K
cve[email protected]CVE-2018-8422
HistorySep 13, 2018 - 12:29 a.m.

CVE-2018-8422

2018-09-1300:29:02
CWE-200
web.nvd.nist.gov
38
cve-2018-8422
information disclosure
windows gdi
windows 7
windows server 2008 r2
nvd

4.3 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:M/Au:N/C:P/I:N/A:N

6.5 Medium

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N

6.3 Medium

AI Score

Confidence

High

0.64 Medium

EPSS

Percentile

97.9%

An information disclosure vulnerability exists when the Windows GDI component improperly discloses the contents of its memory, aka “Windows GDI Information Disclosure Vulnerability.” This affects Windows 7, Windows Server 2008 R2. This CVE ID is unique from CVE-2018-8424.

Affected configurations

Vulners
NVD
Node
microsoftwindows_7Match32-bit Systems Service Pack 1
OR
microsoftwindows_7Matchx64-based Systems Service Pack 1
OR
microsoftwindows_server_2008_r2MatchItanium-Based Systems Service Pack 1
OR
microsoftwindows_server_2008_r2Matchx64-based Systems Service Pack 1
OR
microsoftwindows_server_2008_r2Matchx64-based Systems Service Pack 1 (Server Core installation)
VendorProductVersionCPE
microsoftwindows_732-bit Systems Service Pack 1cpe:2.3:o:microsoft:windows_7:32-bit Systems Service Pack 1:*:*:*:*:*:*:*
microsoftwindows_7x64-based Systems Service Pack 1cpe:2.3:o:microsoft:windows_7:x64-based Systems Service Pack 1:*:*:*:*:*:*:*
microsoftwindows_server_2008_r2Itanium-Based Systems Service Pack 1cpe:2.3:o:microsoft:windows_server_2008_r2:Itanium-Based Systems Service Pack 1:*:*:*:*:*:*:*
microsoftwindows_server_2008_r2x64-based Systems Service Pack 1cpe:2.3:o:microsoft:windows_server_2008_r2:x64-based Systems Service Pack 1:*:*:*:*:*:*:*
microsoftwindows_server_2008_r2x64-based Systems Service Pack 1 (Server Core installation)cpe:2.3:o:microsoft:windows_server_2008_r2:x64-based Systems Service Pack 1 (Server Core installation):*:*:*:*:*:*:*

CNA Affected

[
  {
    "product": "Windows 7",
    "vendor": "Microsoft",
    "versions": [
      {
        "status": "affected",
        "version": "32-bit Systems Service Pack 1"
      },
      {
        "status": "affected",
        "version": "x64-based Systems Service Pack 1"
      }
    ]
  },
  {
    "product": "Windows Server 2008 R2",
    "vendor": "Microsoft",
    "versions": [
      {
        "status": "affected",
        "version": "Itanium-Based Systems Service Pack 1"
      },
      {
        "status": "affected",
        "version": "x64-based Systems Service Pack 1"
      },
      {
        "status": "affected",
        "version": "x64-based Systems Service Pack 1 (Server Core installation)"
      }
    ]
  }
]

4.3 Medium

CVSS2

Attack Vector

NETWORK

Attack Complexity

MEDIUM

Authentication

NONE

Confidentiality Impact

PARTIAL

Integrity Impact

NONE

Availability Impact

NONE

AV:N/AC:M/Au:N/C:P/I:N/A:N

6.5 Medium

CVSS3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

NONE

User Interaction

REQUIRED

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.0/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:N/A:N

6.3 Medium

AI Score

Confidence

High

0.64 Medium

EPSS

Percentile

97.9%