Vulnerability record · CVE-2019-0903 · published 16 May 2019
CVE-2019-0903: Windows GDI memory handling remote code execution
Microsoft · Windows 10 1507
Windows Graphics Device Interface (GDI) mishandles objects in memory, allowing remote code execution. The record gives no root-cause detail beyond this, but the flaw affects a broad set of Windows client and server releases and is listed in CISA's Known Exploited Vulnerabilities catalog.
Description
A remote code execution vulnerability exists in the way that the Windows Graphics Device Interface (GDI) handles objects in the memory, aka 'GDI+ Remote Code Execution Vulnerability'.
CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H
Automated analysis
high priorityNetwork-reachable code execution with known exploitation in the wild (CISA KEV) and a high EPSS percentile, though it requires user interaction.
What it is
Windows Graphics Device Interface (GDI) mishandles objects in memory, allowing remote code execution. The record gives no root-cause detail beyond this, but the flaw affects a broad set of Windows client and server releases and is listed in CISA's Known Exploited Vulnerabilities catalog.
Impact
An attacker who gets code to run in the context of the affected process can execute arbitrary code on the target system, with high impact to confidentiality, integrity and availability per the CVSS vector.
Attack surface
The vector is network-reachable (AV:N) with no privileges required (PR:N), but user interaction is required (UI:R), so exploitation depends on a victim opening or rendering crafted content that reaches GDI.
Exploitation
CVE-2019-0903 is in CISA KEV (added 2022-03-25, due 2022-04-15), indicating known exploitation in the wild; EPSS 30-day probability is 0.21713 (97.5th percentile). No ransomware campaign use is recorded.
What to do
- Apply the Microsoft security update referenced in the vendor advisory for all affected Windows versions.
- Prioritize patching internet-facing and user-workstation systems, since exploitation requires a victim to render crafted content.
- Restrict or block untrusted files and content types that invoke GDI rendering where business needs allow.
- Track KEV remediation deadlines and confirm all listed Windows builds are covered.
Detection
- Monitor for processes spawning unexpectedly from applications that render images or documents (for example Office, browsers, image viewers).
- Alert on suspicious child processes or script interpreters launched by GDI-using applications.
- Hunt for known exploitation artifacts and unusual memory-corruption crash patterns in GDI-related processes.
- Verify patch state of all affected Windows 7, 8.1, 10 and Server builds against the vendor advisory.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Exploitation in the wild
CISA added CVE-2019-0903 to the Known Exploited Vulnerabilities catalog on 25 March 2022 as "Microsoft GDI Remote Code Execution Vulnerability". Required action: Apply updates per vendor instructions. Federal deadline 15 April 2022.
Affected products
16 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-0903 | PatchVendor Advisory |
| https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2019-0903 | PatchVendor Advisory |
| https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2019-0903 | US Government Resource |
Track CVE-2019-0903 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2019-0903), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.