CISA Known Exploited Vulnerability
This vulnerability is actively exploited in the wild and listed in the CISA Known Exploited Vulnerabilities catalog.
Remediation Deadline: Apr 15, 2022
Description
A remote code execution vulnerability exists in the way that the Windows Graphics Device Interface (GDI) handles objects in the memory. An attacker who successfully exploited this vulnerability could take control of the affected system.
EPSS — Exploit Probability
34.4%
Higher than 96.9% of all CVEs
Required Action
https://nvd.nist.gov/vuln/detail/CVE-2019-0903
Risk Assessment
ELEVATEDIn CISA KEV
Details
- Severity
- High
- EPSS
- 34.4%
- CISA KEV
- Yes
- Ransomware
- Unknown
- Articles
- 0
Timeline
Published
Mar 25, 2022
Added to KEV
Mar 25, 2022
Remediation Due
Apr 15, 2022