HTTP: Microsoft Windows GDI CVE-2018-0817 Elevation of Privilege

This signature detects attempts to exploit a known vulnerability against Microsoft Windows GDI. A successful attack could allow the attacker to execute arbitrary commands with elevated privileges.

Extended Description

The Windows Graphics Device Interface (GDI) in Microsoft Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8.1 and RT 8.1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, 1703, and 1709, Windows Server 2016 and Windows Server, version 1709 allows an elevation of privilege vulnerability due to the way objects are handled in memory, aka "Windows GDI Elevation of Privilege Vulnerability". This CVE is unique from CVE-2018-0815 and CVE-2018-0816.

Affected Products

Microsoft windows_server_2016

References

CVE: CVE-2018-0817

Short Name
HTTP:STC:DL:CVE-2018-0817-EOP
Severity
Minor
Recommended
True
Recommended Action
Drop
Category
HTTP
Keywords
CVE-2018-0817 Elevation GDI Microsoft Privilege Windows of
Release Date
03/13/2018
Supported Platforms

srx-branch-12.3

srx-19.3

srx-branch-19.3

vsrx3bsd-19.2

srx-branch-19.4

vsrx-19.4

mx-12.3

mx-19.4

vmx-19.4

mx-19.3

vsrx3bsd-19.4

srx-19.4

vsrx-12.3

vmx-19.3

vsrx-19.2

srx-12.3

Sigpack Version
3590
False Positive
Unknown
Vendors

Microsoft

CVSS Score

6.9

Found a potential security threat?