安全研究

安全漏洞
Windows GDI信息泄露漏洞(CVE-2020-1468)

发布日期:2020-07-14
更新日期:2020-07-27

受影响系统:
Microsoft Windows Server version 2004 (Server Core Inst
Microsoft Windows Server version 1909 (Server Core Inst
Microsoft Windows Server version 1903 (Server Core Inst
Microsoft Windows Server 2019 (Server Core Installation
Microsoft Windows Server 2019
Microsoft Windows Server 2016 (Server Core Installation
Microsoft Windows Server 2016
Microsoft Windows Server 2012 R2 (Server Core installat
Microsoft Windows Server 2012 R2
Microsoft Windows Server 2012 (Server Core installation
Microsoft Windows Server 2012
Microsoft Windows Server 2008 R2 for x64-based Systems
Microsoft Windows Server 2008 R2 for x64-based Systems
Microsoft Windows Server 2008 for x64-based Systems Ser
Microsoft Windows Server 2008 for 32-bit Systems Servic
Microsoft Windows 7 Windows 7 for x64-based System
Microsoft Windows 7 Windows 7 for 32-bit Systems S
Microsoft Windows 10 Version 2004 for x64-based Sys
Microsoft Windows 10 Version 2004 for ARM64-based S
Microsoft Windows 10 Version 2004 for 32-bit System
Microsoft Windows 10 Version 1909 for x64-based Sys
Microsoft Windows 10 Version 1909 for ARM64-based S
Microsoft Windows 10 Version 1909 for 32-bit System
Microsoft Windows 10 Version 1903 for x64-based Sys
Microsoft Windows 10 Version 1903 for ARM64-based S
Microsoft Windows 10 Version 1903 for 32-bit System
Microsoft Windows 10 Version 1809 for x64-based Sys
Microsoft Windows 10 Version 1809 for ARM64-based S
Microsoft Windows 10 Version 1809 for 32-bit System
Microsoft Windows 10 Version 1803 for x64-based Sys
Microsoft Windows 10 Version 1803 for ARM64-based S
Microsoft Windows 10 Version 1803 for 32-bit System
Microsoft Windows 10 Version 1709 for x64-based Sys
Microsoft Windows 10 Version 1709 for ARM64-based S
Microsoft Windows 10 Version 1709 for 32-bit System
Microsoft Windows 10 version 1607 for x64-based Sys
Microsoft Windows 10 Version 1607 for x64-based Sys
Microsoft Windows 10 version 1607 for 32-bit System
Microsoft Windows 10 Version 1607 for 32-bit System
Microsoft Windows 10 for x64-based Systems
Microsoft Windows 10 for 32-bit Systems
Microsoft Windows RT 8.1
Microsoft Windows RT
Microsoft Windows 8.1 for x64-based Systems
Microsoft Windows 8.1 for 32-bit Systems
描述:
CVE(CAN) ID: CVE-2020-1468

Microsoft Windows是美国微软(Microsoft)公司为个人设备提供的一套操作系统。Microsoft Windows Server是微软的一套服务器操作系统。Windows Graphics Device Interface(GDI)是其中的一个图形设备接口。
Windows GDI组件不正确地披露其内存的内容时,存在信息泄露漏洞。 攻击者成功利用此漏洞可以获得信息,以进一步危害用户的系统。

<*来源:HAO LI (VenusTech ADLab )
  *>

建议:
厂商补丁:

Microsoft
---------
目前厂商已经发布了升级补丁以修复这个安全问题:

https://portal.msrc.microsoft.com/en-US/security-guidance/advisory/CVE-2020-1468

浏览次数:941
严重程度:0(网友投票)
本安全漏洞由绿盟科技翻译整理,版权所有,未经许可,不得转载
绿盟科技给您安全的保障