CVE-2020-17098HighCVSS 5.5
Windows GDI+ Information Disclosure Vulnerability
🔗 CVE IDs covered (1)
📋 Description
What type of information could be disclosed by this vulnerability? The type of information that could be disclosed if an attacker successfully exploited this vulnerability is memory layout - the vulnerability allows an attacker to collect information that facilitates predicting addressing of the memory.
🎯 Affected products44
- Windows 10 Version 1607 for 32-bit Systems
- Windows 10 Version 1607 for x64-based Systems
- Windows 10 Version 1803 for 32-bit Systems
- Windows 10 Version 1803 for ARM64-based Systems
- Windows 10 Version 1803 for x64-based Systems
- Windows 10 Version 1809 for 32-bit Systems
- Windows 10 Version 1809 for ARM64-based Systems
- Windows 10 Version 1809 for x64-based Systems
- Windows 10 Version 1903 for 32-bit Systems
- Windows 10 Version 1903 for ARM64-based Systems
- Windows 10 Version 1903 for x64-based Systems
- Windows 10 Version 1909 for 32-bit Systems
- Windows 10 Version 1909 for ARM64-based Systems
- Windows 10 Version 1909 for x64-based Systems
- Windows 10 Version 2004 for 32-bit Systems
- Windows 10 Version 2004 for ARM64-based Systems
- Windows 10 Version 2004 for x64-based Systems
- Windows 10 Version 20H2 for 32-bit Systems
- Windows 10 Version 20H2 for ARM64-based Systems
- Windows 10 for 32-bit Systems
- Windows 10 for x64-based Systems
- Windows 7 for 32-bit Systems Service Pack 1
- Windows 7 for x64-based Systems Service Pack 1
- Windows 8.1 for 32-bit systems
- Windows 8.1 for x64-based systems
- Windows RT 8.1
- Windows Server 2008 R2 for x64-based Systems Service Pack 1
- Windows Server 2008 R2 for x64-based Systems Service Pack 1 (Server Core installation)
- Windows Server 2008 for 32-bit Systems Service Pack 2
- Windows Server 2008 for 32-bit Systems Service Pack 2 (Server Core installation)
- +14 more not shown
✅ Remediation
KB4592438 (Security Update) KB4592446 (Security Update) KB4592440 (Security Update) KB4592449 (Security Update) KB4592464 (Security Update) KB4593226 (Security Update) KB4592471 (Monthly Rollup) — fixed build 6.1.7601.24563 KB4592503 (Security Only) KB4592484 (Monthly Rollup) KB4592495 (Security Only) KB4592498 (Monthly Rollup) — fixed build 6.0.6003.20999 KB4592504 (Security Only) KB4592468 (Monthly Rollup) KB4592497 (Security Only)
🔗 References (29)
- advisoryhttps://msrc.microsoft.com/update-guide/vulnerability/CVE-2020-17098
- patchhttps://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB4592438
- referencehttps://support.microsoft.com/help/4592438
- patchhttps://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB4592446
- referencehttps://support.microsoft.com/help/4592446
- patchhttps://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB4592440
- referencehttps://support.microsoft.com/help/4592440
- patchhttps://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB4592449
- referencehttps://support.microsoft.com/help/4592449
- patchhttps://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB4592464
- referencehttps://support.microsoft.com/help/4592464
- patchhttps://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB4593226
- referencehttps://support.microsoft.com/help/4593226
- patchhttps://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB4592471
- referencehttps://support.microsoft.com/help/4592471
- patchhttps://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB4592503
- referencehttps://support.microsoft.com/help/4592503
- patchhttps://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB4592484
- referencehttps://support.microsoft.com/help/4592484
- patchhttps://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB4592495
- referencehttps://support.microsoft.com/help/4592495
- patchhttps://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB4592498
- referencehttps://support.microsoft.com/help/4592498
- patchhttps://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB4592504
- referencehttps://support.microsoft.com/help/4592504
- patchhttps://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB4592468
- referencehttps://support.microsoft.com/help/4592468
- patchhttps://catalog.update.microsoft.com/v7/site/Search.aspx?q=KB4592497
- referencehttps://support.microsoft.com/help/4592497