High severity8.8NVD Advisory· Published Aug 15, 2018· Updated Jun 17, 2026
CVE-2018-8397
CVE-2018-8397
Description
A remote code execution vulnerability exists in the way that the Windows Graphics Device Interface (GDI) handles objects in the memory, aka "GDI+ Remote Code Execution Vulnerability." This affects Windows Server 2008, Windows 7, Windows Server 2008 R2.
Affected products
8cpe:2.3:o:microsoft:windows_server_2008:-:sp2:*:*:*:*:*:*+ 4 more
- cpe:2.3:o:microsoft:windows_server_2008:-:sp2:*:*:*:*:*:*
- cpe:2.3:o:microsoft:windows_server_2008:r2:sp1:*:*:*:*:itanium:*
- cpe:2.3:o:microsoft:windows_server_2008:r2:sp1:*:*:*:*:x64:*
- (no CPE)range: 32-bit Systems Service Pack 2
- (no CPE)range: Itanium-Based Systems Service Pack 1
Patches
Vulnerability mechanics
References
3- portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2018-8397nvdPatchVendor Advisory
- www.securityfocus.com/bid/104994nvdThird Party AdvisoryVDB Entry
- www.securitytracker.com/id/1041460nvdThird Party AdvisoryVDB Entry
News mentions
0No linked articles in our index yet.