CVE-2019-1047 is an information disclosure vulnerability in the Windows GDI component affecting Windows 7 and Windows Server 2008. An attacker could exploit this by convincing a user to open a malicious document or visit an untrusted webpage, leading to the disclosure of memory contents. With a CVSS score of 4.7 (Medium), exploitation requires low privileges and high attack complexity, but could result in high confidentiality impact. The vulnerability is not known to be actively exploited, and there is no public exploit code available in Metasploit, Nuclei, or ExploitDB. Community discussion and media coverage are minimal, with only one mention and one article identified, indicating low public attention. This vulnerability is not listed in CISA's KEV catalog.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:microsoft:windows_7:-:sp1:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:microsoft:windows_server_2008:-:sp2:*:*:*:*:*:* | ||
r2CPE matchmatch criteria | cpe:2.3:o:microsoft:windows_server_2008:r2:sp1:*:*:*:*:itanium:* | ||
r2CPE matchmatch criteria | cpe:2.3:o:microsoft:windows_server_2008:r2:sp1:*:*:*:*:x64:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.4 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.