March 25, 2022 · Applied Cybernetics Group
CVE-2019-0903 — Microsoft Graphics Device Interface (GDI)
Microsoft GDI Remote Code Execution Vulnerability
- Added to KEV
2022-03-25- Federal due date
2022-04-15- Vendor
- Microsoft
- Product
- Graphics Device Interface (GDI)
- EPSS
- 97.1th percentile (score 0.344, as of
2026-06-08) - NVD CVSS v3.1
- —
- Ransomware use
- Unknown
- Upstream
- https://nvd.nist.gov/vuln/detail/CVE-2019-0903
CISA short description
A remote code execution vulnerability exists in the way that the Windows Graphics Device Interface (GDI) handles objects in the memory. An attacker who successfully exploited this vulnerability could take control of the affected system.
Required action
Apply updates per vendor instructions.