CVE-2018-0750 is an information disclosure vulnerability within the Windows GDI component, affecting Windows 7 SP1 and Windows Server 2008 SP2 and R2 SP1. This flaw, also known as a "Windows Elevation of Privilege Vulnerability," stems from how objects are handled in memory. It carries a CVSS score of 5.5 (Medium), indicating a local attack vector with low complexity, requiring low privileges, and primarily leading to high confidentiality impact without affecting integrity or availability. While there is no known public exploit code (Metasploit, Nuclei, ExploitDB) and it is not listed in CISA's KEV catalog, it has received minimal community discussion and media coverage, suggesting low active exploitation or public interest.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:microsoft:windows_7:-:sp1:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:microsoft:windows_server_2008:-:sp2:*:*:*:*:*:* | ||
r2CPE matchmatch criteria | cpe:2.3:o:microsoft:windows_server_2008:r2:sp1:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.