An information disclosure vulnerability exists in the way that the Windows Graphics Device Interface (GDI) handles objects in memory, allowing an attacker to retrieve information from a targeted system, aka 'Windows GDI Information Disclosure Vulnerability'.
The product reads data past the end, or before the beginning, of the intended buffer.
Link | Tags |
---|---|
https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2020-0744 | patch vendor advisory |
https://www.zerodayinitiative.com/advisories/ZDI-20-552/ | vdb entry third party advisory |
https://www.zerodayinitiative.com/advisories/ZDI-20-578/ | vdb entry third party advisory |